project-auditor-fixes
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill involves the agent ingesting and acting upon data from an external tool output (CSV) which is derived from the project's source code and assets.
- Ingestion points: CSV output file (e.g.,
my.csv) generated by theunity command audittool, containing issue descriptions and recommendations. - Boundary markers: None defined to separate tool output from instructions.
- Capability inventory: The agent can modify files, write to version control, install packages, and execute shell commands via the Unity CLI.
- Sanitization: None described for the CSV data before processing.
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the
com.unity.project-auditor-rulespackage using the Unity CLI if analysis rules are missing. This is an expected package installation from the platform vendor's ecosystem.
Audit Metadata