{"data":{"skill":{"slug":"dirtybitgames-unity-editor","name":"unity-editor","icon":"📦","repo":"https://github.com/DirtybitGames/unityctl/tree/main/examples/unity-editor","status":"approved","author":"DirtybitGames","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"7318ef6f-b595-48e3-9d0d-52bb05e81d3b","skill_id":"56f12a70-c0aa-4c3a-8887-cf7badaabd37","version":2,"content_hash":"4f66c0c2325f0a20c37107a1c8b83823","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"The skill enables remote control of Unity Editor through a local bridge daemon. While it requires external command execution and network communication, these capabilities are necessary for its stated purpose. The tool binds only to localhost and doesn't expose remote access by default.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"examples/unity-editor/SKILL.md","line_end":96,"line_start":22}]},{"factor":"network","evidence":[{"file":"ARCHITECTURE.md","line_end":60,"line_start":52}]},{"factor":"filesystem","evidence":[{"file":"examples/unity-editor/SKILL.md","line_end":92,"line_start":91}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Arbitrary C# Code Execution","locations":[{"file":"examples/unity-editor/SKILL.md","line_end":99,"line_start":75}],"description":"The skill allows execution of arbitrary C# code in Unity Editor through 'unityctl script execute' command. While this is documented functionality for debugging, it could be misused to execute malicious code within the Unity environment."}],"low_findings":[{"title":"Local Network Communication","locations":[{"file":"ARCHITECTURE.md","line_end":60,"line_start":52}],"description":"The tool uses HTTP and WebSocket connections on localhost for communication between CLI, bridge daemon, and Unity Editor. While this is necessary for functionality, it represents a network attack surface."}],"dangerous_patterns":[],"files_scanned":4,"total_lines":374,"audit_model":"claude","audited_at":"2026-01-10T14:03:20.485+00:00","created_at":"2026-01-11T05:34:22.803286+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}