{"data":{"skill":{"slug":"dirtybitgames-unity-editor","name":"unity-editor","icon":"📦","repo":"https://github.com/DirtybitGames/unityctl/tree/main/examples/unity-editor","status":"approved","author":"DirtybitGames","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"d990fee4-aa63-49b0-8693-3a092c56a152","skill_id":"56f12a70-c0aa-4c3a-8887-cf7badaabd37","version":6,"content_hash":"6c1de8f17de5f644cbbcf07be3560c00","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis flagged many command examples, but review shows they are Markdown instructions for expected unityctl operations, not Ruby runtime backticks. The skill intentionally enables Unity CLI control and arbitrary C# execution in the editor, which is legitimate for trusted projects but can modify project state or inspect local data. No evidence found for prompt injection, network exfiltration, screenshot upload, or weak cryptography.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":15,"line_start":13},{"file":"SKILL.md","line_end":23,"line_start":21},{"file":"SKILL.md","line_end":34,"line_start":30},{"file":"SKILL.md","line_end":40,"line_start":37},{"file":"SKILL.md","line_end":46,"line_start":43},{"file":"SKILL.md","line_end":54,"line_start":49},{"file":"SKILL.md","line_end":60,"line_start":57},{"file":"SKILL.md","line_end":66,"line_start":63},{"file":"SKILL.md","line_end":71,"line_start":69},{"file":"SKILL.md","line_end":92,"line_start":90},{"file":"SKILL.md","line_end":97,"line_start":95},{"file":"SKILL.md","line_end":106,"line_start":103},{"file":"SKILL.md","line_end":117,"line_start":111},{"file":"SKILL.md","line_end":134,"line_start":132},{"file":"SKILL.md","line_end":152,"line_start":150},{"file":"SKILL.md","line_end":170,"line_start":168},{"file":"SKILL.md","line_end":176,"line_start":174},{"file":"SKILL.md","line_end":188,"line_start":180}]},{"factor":"scripts","evidence":[{"file":"SKILL.md","line_end":99,"line_start":73},{"file":"SKILL.md","line_end":170,"line_start":119}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Arbitrary C# Execution in Unity Editor","locations":[{"file":"SKILL.md","line_end":99,"line_start":73},{"file":"SKILL.md","line_end":170,"line_start":119}],"confidence":0.88,"description":"The skill instructs agents to run arbitrary C# through unityctl script execution. This is a legitimate debugging feature, but it can inspect or change Unity project state and should be limited to trusted repositories.","confidence_reasoning":"The file explicitly describes executing arbitrary C# via Roslyn and gives multiple script execution examples. The context is legitimate Unity debugging, so this is elevated risk rather than confirmed malicious behavior."},{"title":"External Unity CLI Command Execution","locations":[{"file":"SKILL.md","line_end":15,"line_start":13},{"file":"SKILL.md","line_end":71,"line_start":21},{"file":"SKILL.md","line_end":97,"line_start":90},{"file":"SKILL.md","line_end":117,"line_start":111}],"confidence":0.84,"description":"The skill directs agents to run unityctl commands that start and stop services, launch Unity, refresh assets, run tests, load scenes, and enter play mode. These commands are expected for the skill, but they can alter local editor and project state.","confidence_reasoning":"The static command findings are real command instructions, but they are Markdown examples rather than hidden shell execution. The risk is operational impact from an AI agent running the documented CLI commands."}],"low_findings":[{"title":"Local Screenshot Capture Privacy Risk","locations":[{"file":"SKILL.md","line_end":71,"line_start":68}],"confidence":0.76,"description":"The static upload finding is a false positive because the file only documents screenshot capture and shows no upload destination. Screenshot capture can still expose project visuals or editor state if used without user intent.","confidence_reasoning":"The command is directly present, but no upload or network behavior appears in the reviewed file. The remaining concern is local privacy exposure from screenshots."},{"title":"Weak Cryptography Static Match Dismissed","locations":[{"file":"SKILL.md","line_end":3,"line_start":3}],"confidence":0.95,"description":"The weak cryptography alert at the frontmatter description is a false positive. No cryptographic algorithm, hashing function, encryption API, or related command is present at that location.","confidence_reasoning":"Line 3 is descriptive text about remote Unity Editor control. I found no evidence of cryptographic code or weak algorithm usage in the skill file."}],"dangerous_patterns":[{"title":"Arbitrary Editor Script Execution","locations":[{"file":"SKILL.md","line_end":99,"line_start":73}],"confidence":0.88,"description":"The documented unityctl script execute command can run user-provided C# inside the editor. This pattern is powerful and should require clear user approval.","confidence_reasoning":"The command and direct-code option are explicitly documented. Legitimate debugging context reduces confidence that it is malicious."},{"title":"AI-Initiated Local Tool Commands","locations":[{"file":"SKILL.md","line_end":71,"line_start":13}],"confidence":0.84,"description":"The skill encourages running local unityctl commands that control the bridge, Unity Editor, tests, logs, scenes, and play mode. These are normal for this skill but should be visible to users.","confidence_reasoning":"The commands are clearly present and affect local tools. I found no obfuscation, persistence, or exfiltration behavior."}],"files_scanned":1,"total_lines":189,"audit_model":"codex","audited_at":"2026-06-29T18:03:21.321+00:00","created_at":"2026-06-29T19:20:57.390382+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}