security-audit skill
Security audit — save tampering, cheat vectors, network exploits, data exposure, input validation. Before public or multiplayer release.
Is the security-audit skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the security-audit skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/Donchitos/Claude-Code-Game-Studios.git /tmp/Claude-Code-Game-Studios mkdir -p ~/.claude/skills cp -r /tmp/Claude-Code-Game-Studios/.claude/skills/security-audit ~/.claude/skills/security-audit
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
!bash "${CLAUDESKILLDIR}/../../hooks/yaml-helper.sh" resolve_config --keys automation
Automation mode: Resolve modes.automation (project.local.yaml → project.yaml → default collaborative). Every AskUserQuestion call and every file write follows .claude/docs/automation-modes.md (collaborative asks always · guided major-only · autonomous logs and proceeds; automationalwaysask categories always prompt).
Security Audit
Security is not optional for any shipped game. Even single-player games have save tampering vectors. Multiplayer games have cheat surfaces, data exposure risks, and denial-of-service potential. This skill systematically audits the codebase for the most common game security failures and produces a prioritised remediation plan.
Run this skill:
- Before any public release (required for the Polish → Release gate)
- Before enabling any online/multiplayer feature
- After implementing any system that reads from disk or network
- When a security-related bug is reported
Output: production/security/security-audit-[date].md
Phase 1: Parse Arguments and Scope
Modes:
- full — all categories (recommended before release)
- network — network/multiplayer only
- save — save file and serialization only
- input — input validation and injection only
- quick — high-severity checks only (fastest, for iterative use)
- No argument — run full
Read project.yaml to determine the following, falling back to .claude/docs/technical-preferences.md for engine/language/platforms when a key is absent or empty:
pattern set, and an engine with no sourced set for a category forces NOT ASSESSED for it.** If engine.name is absent or empty, say so in the report and treat every grep category as NOT ASSESSED; do not fall back to the Godot lists because they are the ones written out in full
- engine.name and engine.language — **load-bearing: they select the Phase 3
in scope. technical-preferences.md has no equivalent fields, so the legacy fallback cannot supply them.
- platform.targets (affects which attack surfaces apply)
- platform.multiplayer and platform.online — whether multiplayer/networking is
ABSENT DOES NOT MEAN false. These keys have a reader —
this skill — and no writer anywhere in the framework: neither
/setup-engine nor /start nor any other skill emits a platform: block,
so on essentially every CCGS project both keys are absent. The previous rule
here defaulted them to false, which meant **Category 2 (Network and
Multiplayer Security) was skipped on every project including genuinely
multiplayer ones** — a security category failing open on a value nothing
sets.
When either key is absent or empty: **do not assume single-player, and do not
skip Category 2.** Ask the user whether the game has multiplayer or online
features. If you cannot ask, run Category 2 anyway and mark it
NOT ASSESSED — multiplayer scope unconfirmed (platform.multiplayer unset,
and no skill sets it), which makes CLEAR TO SHIP unreachable per Phase 5.
Over-scanning a single-player game costs a few minutes; under-scanning a
multiplayer one ships the category unrun.
Set them explicitly with /settings platform.multiplayer=true (they are
project-wide, so --local is refused). Recording it in project.yaml is the
fix; this rule is the guard for until someone does.
Phase 2: Spawn Security Engineer
Spawn security-engineer via Agent. Pass:
- The audit scope/mode
- Engine and language (from project.yaml, else technical preferences)
- A manifest of all source directories: the resolved code root (per .claude/docs/code-root-resolution.md), assets/data/, any config files
The security-engineer runs the audit across 6 categories (see Phase 3). Collect their full findings before proceeding.
Phase 3: Audit Categories
The security-engineer evaluates each of the following. Skip categories not applicable to the project scope.
Engine pattern sets — read this before any Category below
Every pattern list in Categories 1–3 was written for Godot. On a Unity or Unreal project they match nothing, and this skill already states what a zero-hit scan means: it renders the report clean, "the most dangerous possible failure for a security audit". That warning was earned along the version axis (File.open vs FileAccess) and the identical hole along the engine axis shipped anyway. Use the table for engine.name resolved in Phase 1.
The Unity and Unreal names above are sourced from this repo's pinned references (docs/engine-reference/unity/modules/{networking,input}.md, docs/engine-reference/unreal/modules/{networking,input}.md), not from recall. Verify them against the pin before use and add what the reference documents that this table omits — it is a floor, not a complete set.
NOT SOURCEABLE is a verdict, not a gap to fill from memory. Neither
reference tree carries a serialization/save module, so the save-API names for
Unity and Unreal cannot be confirmed here. **Do not write them from training
data.** A confidently wrong pattern list is worse in this skill than in any
other: it produces a scan that looks thorough, finds nothing, and reads as a
pass. Where the table says NOT SOURCEABLE, that category is NOT ASSESSED
for this engine — see Phase 5. To close it properly, add the module to
docs/engine-reference// first; then this table can cite it.
Category 1: Save File and Serialization Security
- Are save files validated before loading? (no blind deserialization)
- Are save file paths constructed from user input? (path traversal risk)
- Are save files checksummed or signed? (tamper detection)
- Does the game trust numeric values from save files without bounds checking?
- Are there any eval() or dynamic code execution calls near save loading?
Grep patterns — check the pinned engine reference before trusting this list (see the API-name warning below): FileAccess, File.open, open(, load, deserialize, parse, parsestring, fromjson, readfile, getvar, bytestovar — check each for validation.
**API names are version-specific and this list is a starting point, not a
complete set. File.open is Godot 3.x**; Godot 4 renamed the class to
FileAccess (docs/engine-reference/godot/breaking-changes.md). Before relying
on these patterns, read docs/engine-reference// for the version this
project pins and add the names it documents. A grep for a class that no longer
exists returns zero hits, and **zero hits in this category renders the report
clean** — which is the most dangerous possible failure for a security audit.
More skills from Donchitos/Claude-Code-Game-Studios
- AadoptBrownfield audit — do existing artifacts actually work? Numbered migration plan. Unlike /project-stage-detect, checks compliance not existence.
- Aarchitecture-decisionCreate an ADR documenting a technical decision: context, alternatives considered, consequences.
- Aarchitecture-reviewTraceability matrix mapping GDD requirements to ADRs. Finds gaps, cross-ADR conflicts, engine compatibility. PASS/CONCERNS/NOT ASSESSED/FAIL.
- Aart-bibleAuthor the Art Bible — visual identity gating asset production. Run before /map-systems.
- Aasset-auditAudit assets against naming conventions, file size budgets, format standards. Finds orphaned assets, missing references.
- Aasset-specPer-asset visual specs plus AI generation prompts from GDDs and character profiles. After the art bible.
- Abalance-checkFind balance outliers, broken progressions, degenerate strategies, economy imbalances in formulas and data. 'Check game balance'.
- AbrainstormGuided concept ideation using professional studio techniques, player psychology, creative exploration.
- Abug-reportStructured bug report from a description, or analyze code for potential bugs. Reproduction steps, severity.
- Abug-triageRe-evaluate open bugs — priority vs severity, assign to sprints, surface systemic trends. Run when the count grows.
- AchangelogAuto-generate a changelog from git commits and sprint data. Internal and player-facing versions.
- Acode-reviewArchitectural code review — coding standards, SOLID, testability, performance concerns.