Scanned skills

unity-technologies/skills unity-cli

Checked the catalogued skill at unity-cli.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 10
D Security

D; retained sample includes a high finding · SD-007 · what this rule accepts as a false positive →

F Permissions

F; retained sample includes a critical finding · SD-004 · what this rule accepts as a false positive →

B Transparency

B; retained sample includes a medium finding · SD-007 · what this rule accepts as a false positive →

10 findings
securityhigh SD-007
SKILL.md
transparencymedium SD-007
SKILL.md
permission_hygienecritical SD-004
references/projects-templates.md
securityhigh SD-022
references/projects-templates.md
securityhigh SD-022
references/projects-templates.md
securityhigh SD-022
references/projects-templates.md
permission_hygienecritical SD-004
references/projects-templates.md
securityhigh SD-022
references/projects-templates.md
securityhigh SD-022
references/projects-templates.md
securityhigh SD-022
references/projects-templates.md
7 suppressed by AI triage
securitycritical SD-013 benign_example
references/build-run-test.md

The snippet documents per-project configuration defaults, not a persistence mechanism modifying shell profiles.

permission_hygienehigh SD-003 benign_example
references/collaboration.md

The text merely documents allowed prefix patterns, with no actual '..' or absolute paths present.

securityhigh SD-022 benign_example
references/config-hub.md

The text merely documents a CLI configuration for DNS lookup, not a malicious exfiltration technique.

securitycritical SD-013 benign_example
references/config-hub.md

The content describes a benign project configuration file, not an actual persistence mechanism.

securitymedium SD-012 benign_example
references/diagnostics-maintenance.md

The content describes informational health checks, not a post‑install script execution.

securityhigh SD-007 benign_example
references/diagnostics-maintenance.md

The document explains outbound network calls the CLI performs, not code that initiates them.

securitycritical SD-009 benign_example
references/diagnostics-maintenance.md

The text merely documents a curl|sh install pattern, not executing such code.