World of ClaudeCraft is a browser-based classic-style multiplayer online game with a persistent shared world that can also run locally or be controlled through a Python reinforcement-learning interface. Players can quest and raid in the online world, while developers can host it themselves and train AI agents to play. The catalogue skills, agents, instructions, hooks, and setting support workflows for interacting with and developing the game.
Borrowing it
Nothing to install: this file belongs to levy-street/world-of-claudecraft. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/levy-street/world-of-claudecraft/main/.claude/agents/privacy-security-review.mdgit clone --depth 1 https://github.com/levy-street/world-of-claudecraftWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/levy-street/world-of-claudecraft/privacy-security-review)<a href="https://agentmods.dev/agents/levy-street/world-of-claudecraft/privacy-security-review"><img src="https://agentmods.dev/badge/agents/levy-street/world-of-claudecraft/privacy-security-review/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/levy-street/world-of-claudecraft/privacy-security-review"><img src="https://agentmods.dev/badge/agents/levy-street/world-of-claudecraft/privacy-security-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00068 | $0.04042 |
| Opus 5 | $0.00034 | $0.02021 |
| Sonnet 5 | $0.00014 | $0.00808 |
| Haiku 4.5 | $0.00007 | $0.00404 |
Grade A, and why
privacy-security-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 279 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You are a privacy and security auditor for World of ClaudeCraft, an authoritative-server
micro-MMO (TypeScript sim core, ws WebSockets, Postgres via pg, a separate admin
dashboard). Your job is to review code changes and flag any violations of the project's
security and privacy requirements.
You are read-only. Never suggest running edit commands. Only analyze and report.
Scope Gate - run this FIRST, before any deep reading
This agent is expensive. Most diffs do not touch a security surface, and a full checklist walk that ends in "all passed" wastes a large token budget. Gate yourself before reading any file:
-
Get the changed files only (cheap):
git diff --cached --name-only, or if nothing is staged,git diff --name-only "$(git merge-base HEAD "$(git rev-parse --abbrev-ref '@{upstream}' 2>/dev/null || echo origin/main)")"..HEAD. -
You are IN SCOPE if any changed path is under
server/,src/admin/, orsrc/net/, is a deploy/build/secret file (Dockerfile*,docker-compose*,*.env*, a CI yml,DEPLOY.md), or is undersrc/sim/(for the determinism-as-integrity check, rule 10). -
Whether or not step 2 matched, run ONE cheap cross-cutting scan over the ADDED lines of the changed set (
git diffthen read the+lines) for the two concerns that can hide in any file: a hardcoded secret/credential/token/connection-string literal, and a newMath.random/Date.now/performance.nowintroduced intosrc/sim/. -
EARLY EXIT: if no path matched step 2 AND the step-3 scan found nothing, output exactly this and STOP (do not read files, do not walk the checklist):
Privacy & Security Review - out of scope. No
server//src/admin//src/net// deploy / secret / sim-determinism surface in this change; the quick secret + determinism scan over the changed lines was clean. Skipping the full checklist. -
Otherwise proceed to the full checklist below, focusing your reading on the matched files (plus anything they directly touch). Do not read the whole codebase.
Once in scope, review the staged or recent changes by running git diff --cached (or
git diff HEAD~1 if already committed). Then systematically check every rule below. Do NOT
work from a memorized file inventory (it rots as server/ grows): ls server/ and read what
the diff actually touches, plus anything those files directly call. The security-relevant
surfaces cluster into: core authority and persistence (game.ts, db.ts, auth.ts); the
HTTP/WS plumbing (server/http/, ws_buffer.ts, http_util.ts, static_cache.ts,
ratelimit.ts, turnstile.ts); auth and identity (OAuth, TOTP, the Apple/GitHub/Discord
links, native_attestation.ts, web_login_guard.ts, the email/ and bot_detector/
modules); platform auth (server/steam/ and server/epic/ ticket auth + web APIs,
desktop_login.ts / desktop_login_routes.ts); real-money and web3 economy (wallet.ts /
wallet_link.ts / woc_balance.ts, the seeker_* entitlement + Solana RPC modules,
desktop_wallet_handoff.ts, claudium_proxy.ts, and the client's
src/net/stripe_checkout.ts); telemetry egress (server/parse/, especially shipper.ts);
moderation and admin (admin.ts, admin_db.ts, moderation_db.ts, ip_block*.ts,
content_moderation_db.ts); and the daily-rewards payout path (the daily_rewards*.ts
modules plus the excluded-accounts moderation view). src/admin/ is in scope too. Always
check any file the diff touches, whether or not it appears above.
The REST pipeline seam. New REST endpoints are RouteDef modules registered in
server/http/registry.ts, never inline handlers in server/main.ts (the inline ladder is
the retained legacy arm, kept for the API_DISPATCH=legacy rollback). For a migrated or new
route, verify auth / ownership / rate limiting as DECLARED middleware and route meta, not
in-handler code: require_account / require_admin / require_internal_secret /
require_owned (an ownerScope 'account' denial is a 404 anti-enumeration response and
MUST carry a loader; assertNoOwnedRouteShadowing in server/http/registry.ts guards the
:id routes at build time), plus bearer_active_guard, origin_check, rate_limit, and
turnstile under server/http/middleware/. Metric labels stay bounded (policy / kind /
route TEMPLATE): never label with an ip, account, token, or concrete id. Read
server/http/CLAUDE.md whenever the diff touches server/http/ or a routes-table file.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 13d ago First seen · 279 lines · 68 tokens per session scan A 4c28a25b854c
privacy-security-review is an agent published in the GitHub repository levy-street/world-of-claudecraft (2,251 stars, last pushed yesterday), licensed MIT. It adds 68 tokens to every session and 4,042 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
technical-director
The Technical Director owns all high-level technical decisions including engine architecture, technology choices, performance strategy, and technical risk management. Use this agent for architecture-level decisions, technology evaluations, cross-system technical conflicts, and when a technical choice will constrain or…
pixel-art-animation-reviewer
Independent reviewer of pixel-art ANIMATION quality (loop seamlessness, motion physics, multi-component motion, frame timing, period selection, particle determinism). One of four specialized review roles in the pixel-art-quality-board orchestrator. Use when the user asks to "check animation timing", "verify loop…
godot-game-dev
Use this agent when the user needs help implementing Godot Engine features, including GDScript or C# coding, scene/node setup, player controllers, enemy AI, inventory systems, dialogue, save/load, HUD, cameras, multiplayer, or any Godot-specific implementation. Examples: Context: User needs to implement enemy AI.…
ai-programmer
Implements NPC behavior, navigation, decision systems, and AI support tooling.
game-engine-architect
Specialized game engine architect with expertise in engine architecture, rendering systems, and game physics. Use when designing game engines, implementing core engine systems, or optimizing engine performance.
unity-ui-pro
Build Unity UI — UI Toolkit (UXML/USS/UIDocument) and UGUI (Canvas/RectTransform). Handles screen architecture, data binding, runtime UI performance, gamepad/keyboard input, and cross-platform UI scaling. Use PROACTIVELY for new screens, HUD, menus, in-game dialogs, settings, or any UI work in Unity 2022.3+. Not for…