asset-transformer-toolkit

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill instructs the agent to programmatically generate C# scripts that are executed within the user's live Unity Editor session. These scripts utilize sensitive Editor-only APIs such as AssetDatabase, Undo, and EditorUtility to modify RuleSet and Importer assets.
  • [COMMAND_EXECUTION]: Documentation within the skill (specifically SECURITY.md) identifies the use of the unity CLI and command eval to run the agent-generated C# code within the editor environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill constructs executable C# code using data retrieved from the local Unity project environment, creating a surface where maliciously crafted project assets could influence script generation.
  • Ingestion points: GetActionsList, GetActionDefinitions, GetImporterTypes, GetImporterProperties, and GetLODRules APIs (referenced in references/ and api-docs/).
  • Boundary markers: None provided to delimit tool outputs within generated scripts.
  • Capability inventory: Modifies project files via Unity C# APIs and executes shell commands via the platform's execution tool.
  • Sanitization: No explicit sanitization or escaping mechanisms are documented for data interpolated into the generated C# strings.
  • [METADATA_POISONING]: The SECURITY.md file contains a self-safety assertion citing historical risk acceptance by a named individual ('Ziyi Zhang'). Per global security analysis rules, such internal claims are treated as data to be evaluated rather than authoritative safety conclusions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 08:47 PM
Security Audit — agent-trust-hub — asset-transformer-toolkit