lighting-design

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate technical documentation and patterns for game lighting across multiple engines (Unity, Unreal, Godot, Three.js). No malicious payloads or harmful instructions were found.
  • [DATA_EXFILTRATION]: The skill does not perform network operations, harvest credentials, or access sensitive system files (e.g., .ssh, .env).
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an ingestion surface by analyzing external engine configuration files. The risk is minimized by the lack of sensitive execution capabilities and the use of specific regex-based validation logic.
  • Ingestion points: Processes files with extensions such as .unity, .uasset, and .tscn via logic defined in references/validations.md.
  • Boundary markers: Skill instructions explicitly require the agent to ground all responses in the provided reference materials and correct users based on that data.
  • Capability inventory: No subprocess execution, network access, or file-system write permissions are requested or used across any skill files.
  • Sanitization: Input is validated against narrow regex patterns targeting lighting-specific parameters (e.g., intensity, shadow bias, lightmap resolution).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:07 AM
Security Audit — agent-trust-hub — lighting-design