metaverse-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides educational content and C# code templates for VR interaction and multiplayer networking. A manual review of the instructions and reference scripts found no evidence of malicious patterns, obfuscation, or unauthorized data access. The code follows standard industry practices for the Unity game engine.
  • [INDIRECT_PROMPT_INJECTION]: A theoretical attack surface was identified in the AvatarManager code template (references/EXAMPLES.md), which describes a pattern for loading NFT metadata from external IPFS or blockchain sources. While this represents a surface for ingesting untrusted data, it is a static educational example rather than active automation logic. Evidence Chain: 1. Ingestion point: AvatarManager.LoadNFTMetadata function in references/EXAMPLES.md. 2. Boundary markers: Absent in the code template. 3. Capability inventory: Bash, Write, Read, and WebSearch tools. 4. Sanitization: Not implemented in the provided template.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — metaverse-expert