Skills Agentes

Security Audit

Audita el juego en busca de vulnerabilidades de seguridad: manipulación de saves, vectores de trampas, exploits de red, exposición de datos y validación de entradas; produce un informe priorizado.

Reemplaza a: Un pentest manual (aunque el propio skill recomienda uno humano para lanzamientos competitivos o monetizados)

Solicitareadglobgrepbashwritetask
Estrellas
24.4k

en todo el repo

Actividad
43

0–100, la ruta de este skill

Actualizado
hace 3 meses

último commit aquí

Commits
0

últimos 90 días

Contexto
2.2k tok

64 tok en reposo

Paquete
1 archivo

9 KB

Instalar

Funciona con cualquier agente que lea SKILL.md

npx -y skills add Donchitos/Claude-Code-Game-Studios --skill security-audit --agent claude-code

Se instala solo en este repositorio.

Este skill runs shell commands, writes to your files.

Qué hace

  • Audita el código en busca de fallos de seguridad: manipulación de saves, vectores de trampas, exploits de red, exposición de datos y validación de entradas
  • Clasifica cada hallazgo por severidad (CRITICAL/HIGH/MEDIUM/LOW) y estado (Open/Accepted Risk/Out of Scope)
  • Genera un informe priorizado con guía de remediación en production/security/security-audit-[date].md
  • Revisa dependencias y plugins de terceros en busca de CVEs conocidos
  • Recomienda si el juego está listo para lanzarse (CLEAR TO SHIP / FIX CRITICALS FIRST / DO NOT SHIP)

Úsalo cuando

  • Antes de cualquier lanzamiento público (requerido para el gate Polish → Release)
  • Antes de habilitar cualquier función online o multijugador
  • Después de implementar un sistema que lee de disco o red
  • Cuando se reporta un bug relacionado con seguridad

No lo uses cuando

    Qué lo activa

    Di cualquiera de estas frases y el agente debería cargar este skill.

    • Haz una auditoría de seguridad completa antes del lanzamiento
    • Revisa solo la seguridad de red y multijugador
    • Audita la validación de guardado de partidas
    • /security-audit quick para revisar hallazgos críticos

    SKILL.md

    En inglés

    Security Audit

    Security is not optional for any shipped game. Even single-player games have save tampering vectors. Multiplayer games have cheat surfaces, data exposure risks, and denial-of-service potential. This skill systematically audits the codebase for the most common game security failures and produces a prioritised remediation plan.

    Run this skill:

    • Before any public release (required for the Polish → Release gate)
    • Before enabling any online/multiplayer feature
    • After implementing any system that reads from disk or network
    • When a security-related bug is reported

    Output: production/security/security-audit-[date].md


    Phase 1: Parse Arguments and Scope

    Modes:

    • full — all categories (recommended before release)
    • network — network/multiplayer only
    • save — save file and serialization only
    • input — input validation and injection only
    • quick — high-severity checks only (fastest, for iterative use)
    • No argument — run full

    Read .claude/docs/technical-preferences.md to determine:

    • Engine and language (affects which patterns to search for)
    • Target platforms (affects which attack surfaces apply)
    • Whether multiplayer/networking is in scope

    Phase 2: Spawn Security Engineer

    Spawn security-engineer via Task. Pass:

    • The audit scope/mode
    • Engine and language from technical preferences
    • A manifest of all source directories: src/, assets/data/, any config files

    The security-engineer runs the audit across 6 categories (see Phase 3). Collect their full findings before proceeding.


    Phase 3: Audit Categories

    The security-engineer evaluates each of the following. Skip categories not applicable to the project scope.

    Category 1: Save File and Serialization Security

    • Are save files validated before loading? (no blind deserialization)
    • Are save file paths constructed from user input? (path traversal risk)
    • Are save files checksummed or signed? (tamper detection)
    • Does the game trust numeric values from save files without bounds checking?
    • Are there any eval() or dynamic code execution calls near save loading?

    Grep patterns: File.open, load, deserialize, JSON.parse, from_json, read_file — check each for validation.

    Category 2: Network and Multiplayer Security (skip if single-player only)

    • Is game state authoritative on the server, or does the client dictate outcomes?
    • Are incoming network packets validated for size, type, and value range?
    • Are player positions and state changes validated server-side?
    • Is there rate limiting on any network calls?
    • Are authentication tokens handled correctly (never sent in plaintext)?
    • Does the game expose any debug endpoints in release builds?

    Grep for: recv, receive, PacketPeer, socket, NetworkedMultiplayerPeer, rpc, rpc_id — check each call site for validation.

    Category 3: Input Validation

    • Are any player-supplied strings used in file paths? (path traversal)
    • Are any player-supplied strings logged without sanitization? (log injection)
    • Are numeric inputs (e.g., item quantities, character stats) bounds-checked before use?
    • Are achievement/stat values checked before being written to any backend?

    Grep for: get_input, Input.get_, input_map, user-facing text fields — check validation.

    Category 4: Data Exposure

    • Are any API keys, credentials, or secrets hardcoded in src/ or assets/?
    • Are debug symbols or verbose error messages included in release builds?
    • Does the game log sensitive player data to disk or console?
    • Are any internal file paths or system information exposed to players?

    Grep for: api_key, secret, password, token, private_key, DEBUG, print( in release-facing code.

    Category 5: Cheat and Anti-Tamper Vectors

    • Are gameplay-critical values stored only in memory, not in easily-editable files?
    • Are any critical game progression flags (e.g., "has paid for DLC") validated server-side?
    • Is there any protection against memory editing tools (Cheat Engine, etc.) for multiplayer?
    • Are leaderboard/score submissions validated before acceptance?

    Note: Client-side anti-cheat is largely unenforceable. Focus on server-side validation for anything competitive or monetised.

    Category 6: Dependency and Supply Chain

    • Are any third-party plugins or libraries used? List them.
    • Do any plugins have known CVEs in the version being used?
    • Are plugin sources verified (official marketplace, reviewed repository)?

    Glob for: addons/, plugins/, third_party/, vendor/ — list all external dependencies.


    Phase 4: Classify Findings

    For each finding, assign:

    Severity:

    Level Definition
    CRITICAL Remote code execution, data breach, or trivially-exploitable cheat that breaks multiplayer integrity
    HIGH Save tampering that bypasses progression, credential exposure, or server-side authority bypass
    MEDIUM Client-side cheat enablement, information disclosure, or input validation gap with limited impact
    LOW Defence-in-depth improvement — hardening that reduces attack surface but no direct exploit exists

    Status: Open / Accepted Risk / Out of Scope


    Phase 5: Generate Report

    # Security Audit Report
    
    **Date**: [date]
    **Scope**: [full | network | save | input | quick]
    **Engine**: [engine + version]
    **Audited by**: security-engineer via /security-audit
    **Files scanned**: [N source files, N config files]
    
    ---
    
    ## Executive Summary
    
    | Severity | Count | Must Fix Before Release |
    |----------|-------|------------------------|
    | CRITICAL | [N] | Yes — all |
    | HIGH | [N] | Yes — all |
    | MEDIUM | [N] | Recommended |
    | LOW | [N] | Optional |
    
    **Release recommendation**: [CLEAR TO SHIP / FIX CRITICALS FIRST / DO NOT SHIP]
    
    ---
    
    ## CRITICAL Findings
    
    ### SEC-001: [Title]
    **Category**: [Save / Network / Input / Data / Cheat / Dependency]
    **File**: `[path]` line [N]
    **Description**: [What the vulnerability is]
    **Attack scenario**: [How a malicious user would exploit it]
    **Remediation**: [Specific code change or pattern to apply]
    **Effort**: [Low / Medium / High]
    
    [repeat per finding]
    
    ---
    
    ## HIGH Findings
    
    [same format]
    
    ---
    
    ## MEDIUM Findings
    
    [same format]
    
    ---
    
    ## LOW Findings
    
    [same format]
    
    ---
    
    ## Accepted Risk
    
    [Any findings explicitly accepted by the team with rationale]
    
    ---
    
    ## Dependency Inventory
    
    | Plugin / Library | Version | Source | Known CVEs |
    |-----------------|---------|--------|------------|
    | [name] | [version] | [source] | [none / CVE-XXXX-NNNN] |
    
    ---
    
    ## Remediation Priority Order
    
    1. [SEC-NNN] — [1-line description] — Est. effort: [Low/Medium/High]
    2. ...
    
    ---
    
    ## Re-Audit Trigger
    
    Run `/security-audit` again after remediating any CRITICAL or HIGH findings.
    The Polish → Release gate requires this report with no open CRITICAL or HIGH items.
    

    Phase 6: Write Report

    Present the report summary (executive summary + CRITICAL/HIGH findings only) in conversation.

    Ask: "May I write the full security audit report to production/security/security-audit-[date].md?"

    Write only after approval.


    Phase 7: Gate Integration

    This report is a required artifact for the Polish → Release gate.

    After remediating findings, re-run: /security-audit quick to confirm CRITICAL/HIGH items are resolved before running /gate-check release.

    If CRITICAL findings exist:

    "⛔ CRITICAL security findings must be resolved before any public release. Do not proceed to /launch-checklist until these are addressed."

    If no CRITICAL/HIGH findings:

    "✅ No blocking security findings. Report written to production/security/. Include this path when running /gate-check release."


    Collaborative Protocol

    • Never assume a pattern is safe — flag it and let the user decide
    • Accepted risk is a valid outcome — some LOW findings are acceptable trade-offs for a solo team; document the decision
    • Multiplayer games have a higher bar — any HIGH finding in a multiplayer context should be treated as CRITICAL
    • This is not a penetration test — this audit covers common patterns; a real pentest by a human security professional is recommended before any competitive or monetised multiplayer launch

    Reproducido de Donchitos/Claude-Code-Game-Studios bajo licencia MIT. Leer esta página en markdown.

    Archivos

    1 archivo en el paquete. Solo se lee SKILL.md al activarse — las referencias se cargan si el skill decide que las necesita.

    Antes de instalar

    Requiere el archivo .claude/docs/technical-preferences.md para conocer motor, lenguaje y plataformas objetivo.

    Detalles

    Creador
    Donchitos
    Categoría
    Seguridad
    Licencia
    MIT
    Recursos incluidos
    Solo SKILL.md
    Código fuente
    Ver SKILL.md

    Etiquetas

    Más de Donchitos/Claude-Code-Game-Studios

    Este repo incluye 73 skills. Si instalas uno, normalmente ya tienes los demás.

    Adopt

    24.4k

    Onboarding brownfield: audita el cumplimiento de formato de los artefactos existentes, clasifica los vacíos por impacto y genera un plan de migración numerado.

    Costo de contexto al activarse
    4.5k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 meses
    herramientas desarrollo

    Crea un Registro de Decisión de Arquitectura (ADR) que documenta una decisión técnica importante, su contexto, alternativas consideradas y consecuencias.

    Costo de contexto al activarse
    4.8k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 meses
    documentos

    Valida que la arquitectura del proyecto cubra por completo los GDD: cruza requisitos con ADR, detecta conflictos entre decisiones y compatibilidad de motor, y da un veredicto PASS/CONCERNS/FAIL.

    Costo de contexto al activarse
    6.7k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 meses
    herramientas desarrollo

    Autoría guiada, sección por sección, del Art Bible. Crea la especificación de identidad visual que condiciona toda la producción de assets. Se ejecuta tras aprobar /brainstorm y antes de /map-systems o de redactar cualquier GDD.

    Costo de contexto al activarse
    3.7k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 meses
    documentos

    Audita los assets del juego según convenciones de nombres, presupuestos de tamaño, formatos estándar y requisitos de pipeline. Identifica assets huérfanos, referencias faltantes e infracciones de estándares.

    Costo de contexto al activarse
    697 tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 meses
    testing qa

    Genera especificaciones visuales por asset y prompts de generación IA a partir de GDDs, docs de nivel o perfiles de personaje. Produce archivos de spec y actualiza el manifiesto maestro.

    Costo de contexto al activarse
    4.1k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 meses
    documentos

    Skills relacionados

    Adopt

    24.4k

    Onboarding brownfield: audita el cumplimiento de formato de los artefactos existentes, clasifica los vacíos por impacto y genera un plan de migración numerado.

    Costo de contexto al activarse
    4.5k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 meses
    herramientas desarrollo

    Crea un Registro de Decisión de Arquitectura (ADR) que documenta una decisión técnica importante, su contexto, alternativas consideradas y consecuencias.

    Costo de contexto al activarse
    4.8k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 meses
    documentos

    Valida que la arquitectura del proyecto cubra por completo los GDD: cruza requisitos con ADR, detecta conflictos entre decisiones y compatibilidad de motor, y da un veredicto PASS/CONCERNS/FAIL.

    Costo de contexto al activarse
    6.7k tok
    Tamaño del paquete
    1 archivo
    Última actualización
    hace 3 meses
    herramientas desarrollo