project-auditor-fixes

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill involves the agent ingesting and acting upon data from an external tool output (CSV) which is derived from the project's source code and assets.
  • Ingestion points: CSV output file (e.g., my.csv) generated by the unity command audit tool, containing issue descriptions and recommendations.
  • Boundary markers: None defined to separate tool output from instructions.
  • Capability inventory: The agent can modify files, write to version control, install packages, and execute shell commands via the Unity CLI.
  • Sanitization: None described for the CSV data before processing.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to install the com.unity.project-auditor-rules package using the Unity CLI if analysis rules are missing. This is an expected package installation from the platform vendor's ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:36 AM
Security Audit — agent-trust-hub — project-auditor-fixes