package-add — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited package-add (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
unity-mcp-cli run-tool package-add --input '{
"packageId": "string_value"
}'For complex input (multi-line strings, code), save the JSON to a file and use: ``bash unity-mcp-cli run-tool package-add --input-file args.json ``>
Or pipe via stdin (recommended): ``bash unity-mcp-cli run-tool package-add --input-file - <<'EOF' {"param": "value"} EOF ``If unity-mcp-cli is not found, either install it globally (npm install -g unity-mcp-cli) or use npx unity-mcp-cli instead. Read the /unity-initial-setup skill for detailed installation instructions.
| Name | Type | Required | Description |
|---|---|---|---|
packageId | string | Yes | The package ID to install. Formats: Package ID 'com.unity.textmeshpro' (installs latest compatible version), Package ID with version '[email protected]', Git URL 'https://github.com/user/repo.git', Git URL with branch/tag 'https://github.com/user/repo.git#v1.0.0', Local path 'file:../MyPackage'. |
{
"type": "object",
"properties": {
"packageId": {
"type": "string"
}
},
"required": [
"packageId"
]
}This tool does not return structured output.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.