Mmcp.market

security-audit skill

by Donchitos·Donchitos/Claude-Code-Game-Studios·25k stars·MIT

Security audit — save tampering, cheat vectors, network exploits, data exposure, input validation. Before public or multiplayer release.

A100/100content scan

Is the security-audit skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the security-audit skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/Donchitos/Claude-Code-Game-Studios.git /tmp/Claude-Code-Game-Studios
mkdir -p ~/.claude/skills
cp -r /tmp/Claude-Code-Game-Studios/.claude/skills/security-audit ~/.claude/skills/security-audit
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

!bash "${CLAUDESKILLDIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation

Automation mode: Resolve modes.automation (project.local.yaml → project.yaml → default collaborative). Every AskUserQuestion call and every file write follows .claude/docs/automation-modes.md (collaborative asks always · guided major-only · autonomous logs and proceeds; automationalwaysask categories always prompt).

Security Audit

Security is not optional for any shipped game. Even single-player games have save tampering vectors. Multiplayer games have cheat surfaces, data exposure risks, and denial-of-service potential. This skill systematically audits the codebase for the most common game security failures and produces a prioritised remediation plan.

Run this skill:

  • Before any public release (required for the Polish → Release gate)
  • Before enabling any online/multiplayer feature
  • After implementing any system that reads from disk or network
  • When a security-related bug is reported

Output: production/security/security-audit-[date].md

Phase 1: Parse Arguments and Scope

Modes:

  • full — all categories (recommended before release)
  • network — network/multiplayer only
  • save — save file and serialization only
  • input — input validation and injection only
  • quick — high-severity checks only (fastest, for iterative use)
  • No argument — run full

Read project.yaml to determine the following, falling back to .claude/docs/technical-preferences.md for engine/language/platforms when a key is absent or empty:

pattern set, and an engine with no sourced set for a category forces NOT ASSESSED for it.** If engine.name is absent or empty, say so in the report and treat every grep category as NOT ASSESSED; do not fall back to the Godot lists because they are the ones written out in full

  • engine.name and engine.language — **load-bearing: they select the Phase 3

in scope. technical-preferences.md has no equivalent fields, so the legacy fallback cannot supply them.

  • platform.targets (affects which attack surfaces apply)
  • platform.multiplayer and platform.online — whether multiplayer/networking is

ABSENT DOES NOT MEAN false. These keys have a reader —

this skill — and no writer anywhere in the framework: neither

/setup-engine nor /start nor any other skill emits a platform: block,

so on essentially every CCGS project both keys are absent. The previous rule

here defaulted them to false, which meant **Category 2 (Network and

Multiplayer Security) was skipped on every project including genuinely

multiplayer ones** — a security category failing open on a value nothing

sets.

When either key is absent or empty: **do not assume single-player, and do not

skip Category 2.** Ask the user whether the game has multiplayer or online

features. If you cannot ask, run Category 2 anyway and mark it

NOT ASSESSED — multiplayer scope unconfirmed (platform.multiplayer unset,

and no skill sets it), which makes CLEAR TO SHIP unreachable per Phase 5.

Over-scanning a single-player game costs a few minutes; under-scanning a

multiplayer one ships the category unrun.

Set them explicitly with /settings platform.multiplayer=true (they are

project-wide, so --local is refused). Recording it in project.yaml is the

fix; this rule is the guard for until someone does.

Phase 2: Spawn Security Engineer

Spawn security-engineer via Agent. Pass:

  • The audit scope/mode
  • Engine and language (from project.yaml, else technical preferences)
  • A manifest of all source directories: the resolved code root (per .claude/docs/code-root-resolution.md), assets/data/, any config files

The security-engineer runs the audit across 6 categories (see Phase 3). Collect their full findings before proceeding.

Phase 3: Audit Categories

The security-engineer evaluates each of the following. Skip categories not applicable to the project scope.

Engine pattern sets — read this before any Category below

Every pattern list in Categories 1–3 was written for Godot. On a Unity or Unreal project they match nothing, and this skill already states what a zero-hit scan means: it renders the report clean, "the most dangerous possible failure for a security audit". That warning was earned along the version axis (File.open vs FileAccess) and the identical hole along the engine axis shipped anyway. Use the table for engine.name resolved in Phase 1.

The Unity and Unreal names above are sourced from this repo's pinned references (docs/engine-reference/unity/modules/{networking,input}.md, docs/engine-reference/unreal/modules/{networking,input}.md), not from recall. Verify them against the pin before use and add what the reference documents that this table omits — it is a floor, not a complete set.

NOT SOURCEABLE is a verdict, not a gap to fill from memory. Neither

reference tree carries a serialization/save module, so the save-API names for

Unity and Unreal cannot be confirmed here. **Do not write them from training

data.** A confidently wrong pattern list is worse in this skill than in any

other: it produces a scan that looks thorough, finds nothing, and reads as a

pass. Where the table says NOT SOURCEABLE, that category is NOT ASSESSED

for this engine — see Phase 5. To close it properly, add the module to

docs/engine-reference// first; then this table can cite it.

Category 1: Save File and Serialization Security

  • Are save files validated before loading? (no blind deserialization)
  • Are save file paths constructed from user input? (path traversal risk)
  • Are save files checksummed or signed? (tamper detection)
  • Does the game trust numeric values from save files without bounds checking?
  • Are there any eval() or dynamic code execution calls near save loading?

Grep patterns — check the pinned engine reference before trusting this list (see the API-name warning below): FileAccess, File.open, open(, load, deserialize, parse, parsestring, fromjson, readfile, getvar, bytestovar — check each for validation.

**API names are version-specific and this list is a starting point, not a

complete set. File.open is Godot 3.x**; Godot 4 renamed the class to

FileAccess (docs/engine-reference/godot/breaking-changes.md). Before relying

on these patterns, read docs/engine-reference// for the version this

project pins and add the names it documents. A grep for a class that no longer

exists returns zero hits, and **zero hits in this category renders the report

clean** — which is the most dangerous possible failure for a security audit.

More skills from Donchitos/Claude-Code-Game-Studios

  • AadoptBrownfield audit — do existing artifacts actually work? Numbered migration plan. Unlike /project-stage-detect, checks compliance not existence.
  • Aarchitecture-decisionCreate an ADR documenting a technical decision: context, alternatives considered, consequences.
  • Aarchitecture-reviewTraceability matrix mapping GDD requirements to ADRs. Finds gaps, cross-ADR conflicts, engine compatibility. PASS/CONCERNS/NOT ASSESSED/FAIL.
  • Aart-bibleAuthor the Art Bible — visual identity gating asset production. Run before /map-systems.
  • Aasset-auditAudit assets against naming conventions, file size budgets, format standards. Finds orphaned assets, missing references.
  • Aasset-specPer-asset visual specs plus AI generation prompts from GDDs and character profiles. After the art bible.
  • Abalance-checkFind balance outliers, broken progressions, degenerate strategies, economy imbalances in formulas and data. 'Check game balance'.
  • AbrainstormGuided concept ideation using professional studio techniques, player psychology, creative exploration.
  • Abug-reportStructured bug report from a description, or analyze code for potential bugs. Reproduction steps, severity.
  • Abug-triageRe-evaluate open bugs — priority vs severity, assign to sprints, surface systemic trends. Run when the count grows.
  • AchangelogAuto-generate a changelog from git commits and sprint data. Internal and player-facing versions.
  • Acode-reviewArchitectural code review — coding standards, SOLID, testability, performance concerns.

All agent skills → · MCP servers