Please do not open a public issue for vulnerabilities involving command execution, credential exposure, path handling, approval bypasses, or Unity Pipeline access.
Use GitHub's private vulnerability reporting feature for this repository. Include the affected version, reproduction steps, impact, and any suggested mitigation. Avoid including real credentials, license files, keystores, or proprietary Unity project content.
Until the first stable release, security fixes are applied to the latest published version on the default branch.
Unity CLI Agent is a local MCP integration. It launches the Unity CLI without a shell, but connected Editor commands and C# eval execute with the authority of the Unity process and current operating-system user. Users must review requested mutations, keep secrets outside model context, and restrict Pipeline runtime exposure to development and QA environments.