ui-uitk

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides legitimate instructions for generating UXML and USS files, which are standard XML and CSS-like formats for Unity UI. No malicious command execution or unauthorized file system access patterns were detected.
  • [SAFE]: The core instructions include a specific security rule: 'EXTERNAL URLs: NEVER use url() with external paths.' This is a significant safety feature that prevents the agent from creating UI assets that could leak data or load malicious resources from the internet.
  • [DYNAMIC_EXECUTION]: The skill provides templates for C# script generation (Manipulators, Custom Elements, Data Binding). While this involves code that will be executed, it follows standard Unity development workflows where code is written to disk and compiled by the Unity Editor, requiring user action (focusing the editor) as a validation step.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads existing project files to perform targeted edits. This creates a potential surface for indirect prompt injection if the project contains malicious comments. However, the risk is mitigated by the fact that the skill operates within a local developer-controlled project environment and its generated outputs are intended for human review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 02:55 PM
Security Audit — agent-trust-hub — ui-uitk