asset-transformer-toolkit
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [DYNAMIC_EXECUTION]: The skill instructs the agent to programmatically generate C# scripts that are executed within the user's live Unity Editor session. These scripts utilize sensitive Editor-only APIs such as
AssetDatabase,Undo, andEditorUtilityto modify RuleSet and Importer assets. - [COMMAND_EXECUTION]: Documentation within the skill (specifically
SECURITY.md) identifies the use of theunityCLI andcommand evalto run the agent-generated C# code within the editor environment. - [INDIRECT_PROMPT_INJECTION]: The skill constructs executable C# code using data retrieved from the local Unity project environment, creating a surface where maliciously crafted project assets could influence script generation.
- Ingestion points:
GetActionsList,GetActionDefinitions,GetImporterTypes,GetImporterProperties, andGetLODRulesAPIs (referenced inreferences/andapi-docs/). - Boundary markers: None provided to delimit tool outputs within generated scripts.
- Capability inventory: Modifies project files via Unity C# APIs and executes shell commands via the platform's execution tool.
- Sanitization: No explicit sanitization or escaping mechanisms are documented for data interpolated into the generated C# strings.
- [METADATA_POISONING]: The
SECURITY.mdfile contains a self-safety assertion citing historical risk acceptance by a named individual ('Ziyi Zhang'). Per global security analysis rules, such internal claims are treated as data to be evaluated rather than authoritative safety conclusions.
Audit Metadata