📦

Audit History

unity-ecs-patterns - 9 audits

Version comparison

Capability and finding changes across audited versions, newest first.

VersionDateResultReview itemsChange vs previous
v9 LatestJul 8, 2026, 11:49 AM No confirmed findings0No capability change
v8 Jul 8, 2026, 11:49 AM No confirmed findings0External commands
v7 Jul 1, 2026, 01:04 AM No confirmed findings0No capability change
v6 Jul 1, 2026, 01:04 AM No confirmed findings0Network access
v5 Jan 21, 2026, 05:14 PM No confirmed findings0 Network accessExternal commands
v4 Jan 17, 2026, 08:37 AM No confirmed findings0No capability change
v3 Jan 17, 2026, 08:37 AM No confirmed findings0Network accessExternal commands
v2 Jan 5, 2026, 05:09 PM No confirmed findings0No capability change
v1 Jan 5, 2026, 05:09 PM No confirmed findings0Baseline

Jul 8, 2026, 11:49 AM

All static command-execution detections are Markdown code fences or C# Unity examples, not executable skill behavior. The hardcoded URLs are reference links to Unity documentation and samples, and no prompt injection or malicious intent was found.

1
Files scanned
627
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jul 8, 2026, 11:49 AM

All static command-execution detections are Markdown code fences or C# Unity examples, not executable skill behavior. The hardcoded URLs are reference links to Unity documentation and samples, and no prompt injection or malicious intent was found.

1
Files scanned
627
Lines analyzed
2
Review items
0
False positives ignored
Audited by: codex

Jul 1, 2026, 01:04 AM

Static analysis flagged markdown code fences, Unity API terms, and reference links. Manual review found no executable shell commands, prompt injection, credential access, data exfiltration, or malicious intent. The remaining network indicator is limited to documentation and sample repository URLs.

1
Files scanned
627
Lines analyzed
1
Review items
3
False positives ignored
Static false positives ignored (3)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
False Positive: Markdown Code Fences Flagged as Shell Execution
The reported external command locations are markdown code fences around Unity C# examples. They do not execute commands or invoke a shell.
The flagged locations are visible markdown fences or C# code sample boundaries. No shell interpreter, process launch API, or command string is present at those lines.
Low
False Positive: Unity ECS Terms Flagged as Blocker Patterns
The weak cryptography and system reconnaissance alerts map to Unity ECS words such as Entity, System, OnCreate, and DestroyEntity in instructional C# examples.
The surrounding context is Unity ECS tutorial code, not cryptographic or reconnaissance behavior. No evidence found of host inspection, weak crypto calls, or malware-like intent.
Low
Documentation URLs Present
The file includes hardcoded links to Unity documentation, Unity ECS samples, and the Burst guide. These are references, not active network requests.
The URLs appear only in a Resources section. There is no code that fetches those URLs, sends data, or directs the agent to contact external services.

Risk Factors

Audited by: codex

Jul 1, 2026, 01:04 AM

Static analysis flagged markdown code fences, Unity API terms, and reference links. Manual review found no executable shell commands, prompt injection, credential access, data exfiltration, or malicious intent. The remaining network indicator is limited to documentation and sample repository URLs.

1
Files scanned
627
Lines analyzed
1
Review items
3
False positives ignored
Static false positives ignored (3)

These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.

Low
False Positive: Markdown Code Fences Flagged as Shell Execution
The reported external command locations are markdown code fences around Unity C# examples. They do not execute commands or invoke a shell.
The flagged locations are visible markdown fences or C# code sample boundaries. No shell interpreter, process launch API, or command string is present at those lines.
Low
False Positive: Unity ECS Terms Flagged as Blocker Patterns
The weak cryptography and system reconnaissance alerts map to Unity ECS words such as Entity, System, OnCreate, and DestroyEntity in instructional C# examples.
The surrounding context is Unity ECS tutorial code, not cryptographic or reconnaissance behavior. No evidence found of host inspection, weak crypto calls, or malware-like intent.
Low
Documentation URLs Present
The file includes hardcoded links to Unity documentation, Unity ECS samples, and the Burst guide. These are references, not active network requests.
The URLs appear only in a Resources section. There is no code that fetches those URLs, sends data, or directs the agent to contact external services.

Risk Factors

Audited by: codex

Jan 21, 2026, 05:14 PM

All 59 static findings are false positives. The skill contains Unity ECS documentation with code examples. Detected patterns (hash functions, system API references, backticks) are legitimate game development patterns and Markdown formatting, not security threats.

2
Files scanned
1,194
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 17, 2026, 08:37 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
806
Lines analyzed
2
Review items
0
False positives ignored

Detected Patterns

Hardcoded URLWeak cryptographic algorithmSystem reconnaissanceRuby/shell backtick execution
Audited by: claude

Jan 17, 2026, 08:37 AM

AI analysis failed after multiple attempts - MANUAL REVIEW REQUIRED before publishing. This skill cannot be auto-published until reviewed by a human.

2
Files scanned
806
Lines analyzed
2
Review items
0
False positives ignored

Detected Patterns

Hardcoded URLWeak cryptographic algorithmSystem reconnaissanceRuby/shell backtick execution
Audited by: claude

Jan 5, 2026, 05:09 PM

Pure documentation skill containing only markdown content about Unity ECS patterns. No executable code, no scripts, no network calls, no filesystem access. This skill provides informational content only.

4
Files scanned
847
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude

Jan 5, 2026, 05:09 PM

Pure documentation skill containing only markdown content about Unity ECS patterns. No executable code, no scripts, no network calls, no filesystem access. This skill provides informational content only.

4
Files scanned
847
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were recorded for this completed audit.
Audited by: claude