uloop-execute-dynamic-code

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and not overtly malicious: it exists to run dynamic Unity Editor code, and its capabilities match that claim. However, it gives an AI agent a powerful local code-execution path with project-modifying effects, so it should be classified as suspicious/high-risk tooling rather than benign. Install provenance is somewhat verifiable but not strong enough to offset the inherent execution risk.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
May 6, 2026, 05:53 AM
Package URL
pkg:socket/skills-sh/hatayama%2FuLoopMCP%2Fuloop-execute-dynamic-code%2F@3c72b47909a169dd5624c16254bb541ae432a8e0