CRIT
MINED116
[MINED116] Workflow uses `secrets.UNITY_MCP_TOOLS` on a `pull_request` trigger: This work…
.github/workflows/copilot-setup-steps.y…:45
CRIT
MINED116
[MINED116] Workflow uses `secrets.UNITY_PASSWORD` on a `pull_request` trigger: This workf…
.github/workflows/copilot-setup-steps.y…:44
CRIT
MINED116
[MINED116] Workflow uses `secrets.UNITY_EMAIL` on a `pull_request` trigger: This workflow…
.github/workflows/copilot-setup-steps.y…:43
HIGH
SEC114
[SEC114] path.join / Path() on user-controlled segment without containment check: filepat…
cli/src/utils/input.ts:38
HIGH
MINED006
[MINED006] Overcatch Baseexception: except BaseException: ... — prevents Ctrl+C and Syste…
Unity-MCP-Server/MCP-Test-Client/mcp_cl…:235
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
Unity-MCP-Plugin/Packages/com.ivanmurza…:227
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
Unity-MCP-Plugin/Packages/com.ivanmurza…:184
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
Unity-MCP-Plugin/Packages/com.ivanmurza…:60
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
Unity-MCP-Plugin/Packages/com.ivanmurza…:71
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
Unity-MCP-Plugin/Packages/com.ivanmurza…:201
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
Unity-MCP-Plugin/Packages/com.ivanmurza…:75
HIGH
DKR014
Dockerfile copies the entire context without .dockerignore
Unity-MCP-Server/Dockerfile:15
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/ReflectorNet.dll` committed…
Unity-MCP-Plugin/Assets/Plugins/NuGet/R…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/System.Text.Json.dll` commi…
Unity-MCP-Plugin/Assets/Plugins/NuGet/S…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.AspNetCore.Signal…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.Extensions.Hostin…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.Extensions.Depend…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.Extensions.FilePr…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.AspNetCore.Signal…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.Bcl.TimeProvider.…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.AspNetCore.Signal…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/System.Memory.dll` committe…
Unity-MCP-Plugin/Assets/Plugins/NuGet/S…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.AspNetCore.Http.C…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.CodeAnalysis.CSha…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.Extensions.Cachin…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/System.Runtime.CompilerServ…
Unity-MCP-Plugin/Assets/Plugins/NuGet/S…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/System.Threading.Tasks.Exte…
Unity-MCP-Plugin/Assets/Plugins/NuGet/S…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/System.Reflection.Metadata.…
Unity-MCP-Plugin/Assets/Plugins/NuGet/S…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/R3.dll` committed in source…
Unity-MCP-Plugin/Assets/Plugins/NuGet/R…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.Bcl.AsyncInterfac…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/System.ComponentModel.Annot…
Unity-MCP-Plugin/Assets/Plugins/NuGet/S…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/System.Numerics.Vectors.dll…
Unity-MCP-Plugin/Assets/Plugins/NuGet/S…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/System.Buffers.dll` committ…
Unity-MCP-Plugin/Assets/Plugins/NuGet/S…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.CodeAnalysis.dll`…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.AspNetCore.Connec…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.Extensions.Diagno…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED134
[MINED134] Binary file `Unity-MCP-Plugin/Assets/Plugins/NuGet/Microsoft.Extensions.Primit…
Unity-MCP-Plugin/Assets/Plugins/NuGet/M…:1
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/release.yml:57
HIGH
MINED115
[MINED115] Action `mukunku/tag-exists-action` pinned to mutable ref `@v1.7.0`: `uses: muk…
.github/workflows/release.yml:45
HIGH
MINED115
[MINED115] Action `WyriHaximus/github-action-get-previous-tag` pinned to mutable ref `@v2…
.github/workflows/release.yml:41
HIGH
MINED115
[MINED115] Action `martinbeentjes/npm-get-version-action` pinned to mutable ref `@v1.3.1`…
.github/workflows/release.yml:35
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/release.yml:28
HIGH
MINED115
[MINED115] Action `anthropics/claude-code-action` pinned to mutable ref `@v1`: `uses: ant…
.github/workflows/claude.yml:61
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/claude.yml:48
HIGH
MINED115
[MINED115] Action `actions/setup-dotnet` pinned to mutable ref `@v5`: `uses: actions/setu…
.github/workflows/claude.yml:41
HIGH
MINED115
[MINED115] Action `actions/setup-node` pinned to mutable ref `@v6`: `uses: actions/setup-…
.github/workflows/deploy.yml:130
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/deploy.yml:127
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/deploy.yml:90
HIGH
MINED115
[MINED115] Action `NuGet/login` pinned to mutable ref `@v1`: `uses: NuGet/login@v1` resol…
.github/workflows/deploy.yml:69
HIGH
MINED115
[MINED115] Action `actions/setup-dotnet` pinned to mutable ref `@v5`: `uses: actions/setu…
.github/workflows/deploy.yml:44
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/deploy.yml:34
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v6`: `uses: actions/checkout…
.github/workflows/copilot-setup-steps.y…:38
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/dotnet/aspnet:9.0` not pinned by digest: `F…
Unity-MCP-Server/Dockerfile:21
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/dotnet/sdk:9.0` not pinned by digest: `FROM…
Unity-MCP-Server/Dockerfile:5
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
commands/tools/validate_json_schema.py:160
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
commands/tools/validate_json_schema.py:124
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
commands/tools/validate_mcp_openai.py:138
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
commands/tools/validate_mcp_openai.py:307
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
commands/tools/validate_mcp_openai.py:194
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
Unity-MCP-Server/MCP-Test-Client/mcp_cl…:108
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
Unity-MCP-Server/MCP-Test-Client/mcp_cl…:61
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
Unity-MCP-Server/MCP-Test-Client/mcp_cl…:114
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
Unity-MCP-Server/MCP-Test-Client/mcp_cl…:68
MED
COMP001
[COMP001] High cognitive complexity: Function `print_tools` has cognitive complexity 16 (…
Unity-MCP-Server/MCP-Test-Client/mcp_cl…:118
MED
COMP001
[COMP001] High cognitive complexity: Function `fetch_tools` has cognitive complexity 22 (…
Unity-MCP-Server/MCP-Test-Client/mcp_cl…:72
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
DKR001
Docker final stage has no non-root USER
Unity-MCP-Server/Dockerfile:21
MED
AIC001
Parallel implementation file sits beside a canonical file
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
COMP001
[COMP001] High cognitive complexity: Function `show_schema_preview` has cognitive complex…
commands/tools/validate_json_schema.py:74
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:11
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:11
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:79
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:17
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC003
Duplicated implementation block across source files
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
LOW
AIC005
Duplicate top-level symbol appears in a patch-style file
Unity-MCP-Plugin/Packages/com.ivanmurza…:1
INFO
MINED064
[MINED064] Python Input Call: input() blocks for stdin. Inappropriate in services.
commands/tools/validate_json_schema.py:176
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
cli/src/utils/manifest.ts:226
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
cli/src/commands/setup-skills.ts:136
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
cli/src/commands/setup-mcp.ts:94
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
cli/src/commands/run-tool-builder.ts:108
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
Unity-MCP-Server/MCP-Test-Client/mcp_cl…:221
INFO
MINED055
[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versi…
Unity-MCP-Plugin/Packages/com.ivanmurza…:62
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
Unity-MCP-Plugin/Packages/com.ivanmurza…:67
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
Unity-MCP-Plugin/Packages/com.ivanmurza…:64
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
Installer/Assets/com.IvanMurzak/AI Game…:106