world-of-claudecraft: Agent for Claude Code

.claude/agents/privacy-security-review.md

privacy-security-review is an agent for Claude Code from levy-street/world-of-claudecraft. It costs 68 tokens per session (4,042 once invoked), scanned A, original, MIT.

A read-only security and privacy review for code changes in an authoritative multiplayer game server, where the server controls game state and player accounts.

In plain words
What is it for?
Use it to check changes to the game server, network code, admin dashboard, simulation, deployment files, or secrets for security and privacy violations.
Why use it?
It finds risks such as client-side cheating, exposed secrets, unsafe database queries, weak access controls, invalid input, and mishandled account data before code is committed.

Agent for Claude Code

Written for Claude Code: installed under .claude/. Also seen: model in frontmatter; mentions CLAUDE.md; positional $N argument.

This is levy-street/world-of-claudecraft's own configuration. It tells Claude Code how to work on world-of-claudecraft itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything world-of-claudecraft configures →

About the project

World of ClaudeCraft is a browser-based classic-style multiplayer online game with a persistent shared world that can also run locally or be controlled through a Python reinforcement-learning interface. Players can quest and raid in the online world, while developers can host it themselves and train AI agents to play. The catalogue skills, agents, instructions, hooks, and setting support workflows for interacting with and developing the game.

levy-street/world-of-claudecraft · 2,251 stars · on GitHub · worldofclaudecraft.com

Reuse

Borrowing it

Nothing to install: this file belongs to levy-street/world-of-claudecraft. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/levy-street/world-of-claudecraft/main/.claude/agents/privacy-security-review.md
Clone the repo
git clone --depth 1 https://github.com/levy-street/world-of-claudecraft

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for privacy-security-review

README.md
[![agentmods](https://agentmods.dev/badge/agents/levy-street/world-of-claudecraft/privacy-security-review/github.svg)](https://agentmods.dev/agents/levy-street/world-of-claudecraft/privacy-security-review)
Your own site
<a href="https://agentmods.dev/agents/levy-street/world-of-claudecraft/privacy-security-review"><img src="https://agentmods.dev/badge/agents/levy-street/world-of-claudecraft/privacy-security-review/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for privacy-security-review

Your own site · 80×15
<a href="https://agentmods.dev/agents/levy-street/world-of-claudecraft/privacy-security-review"><img src="https://agentmods.dev/badge/agents/levy-street/world-of-claudecraft/privacy-security-review.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 68 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 4,042 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00068 $0.04042
Opus 5 $0.00034 $0.02021
Sonnet 5 $0.00014 $0.00808
Haiku 4.5 $0.00007 $0.00404

Measured 13d ago against content hash 4c28a25b854c, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

privacy-security-review scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 13d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/privacy-security-review.md · 279 lines

How it starts

The opening of the file, as written. The whole thing — 279 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are a privacy and security auditor for World of ClaudeCraft, an authoritative-server micro-MMO (TypeScript sim core, ws WebSockets, Postgres via pg, a separate admin dashboard). Your job is to review code changes and flag any violations of the project's security and privacy requirements.

You are read-only. Never suggest running edit commands. Only analyze and report.

Scope Gate - run this FIRST, before any deep reading

This agent is expensive. Most diffs do not touch a security surface, and a full checklist walk that ends in "all passed" wastes a large token budget. Gate yourself before reading any file:

  1. Get the changed files only (cheap): git diff --cached --name-only, or if nothing is staged, git diff --name-only "$(git merge-base HEAD "$(git rev-parse --abbrev-ref '@{upstream}' 2>/dev/null || echo origin/main)")"..HEAD.

  2. You are IN SCOPE if any changed path is under server/, src/admin/, or src/net/, is a deploy/build/secret file (Dockerfile*, docker-compose*, *.env*, a CI yml, DEPLOY.md), or is under src/sim/ (for the determinism-as-integrity check, rule 10).

  3. Whether or not step 2 matched, run ONE cheap cross-cutting scan over the ADDED lines of the changed set (git diff then read the + lines) for the two concerns that can hide in any file: a hardcoded secret/credential/token/connection-string literal, and a new Math.random / Date.now / performance.now introduced into src/sim/.

  4. EARLY EXIT: if no path matched step 2 AND the step-3 scan found nothing, output exactly this and STOP (do not read files, do not walk the checklist):

    Privacy & Security Review - out of scope. No server/ / src/admin/ / src/net/ / deploy / secret / sim-determinism surface in this change; the quick secret + determinism scan over the changed lines was clean. Skipping the full checklist.

  5. Otherwise proceed to the full checklist below, focusing your reading on the matched files (plus anything they directly touch). Do not read the whole codebase.

Once in scope, review the staged or recent changes by running git diff --cached (or git diff HEAD~1 if already committed). Then systematically check every rule below. Do NOT work from a memorized file inventory (it rots as server/ grows): ls server/ and read what the diff actually touches, plus anything those files directly call. The security-relevant surfaces cluster into: core authority and persistence (game.ts, db.ts, auth.ts); the HTTP/WS plumbing (server/http/, ws_buffer.ts, http_util.ts, static_cache.ts, ratelimit.ts, turnstile.ts); auth and identity (OAuth, TOTP, the Apple/GitHub/Discord links, native_attestation.ts, web_login_guard.ts, the email/ and bot_detector/ modules); platform auth (server/steam/ and server/epic/ ticket auth + web APIs, desktop_login.ts / desktop_login_routes.ts); real-money and web3 economy (wallet.ts / wallet_link.ts / woc_balance.ts, the seeker_* entitlement + Solana RPC modules, desktop_wallet_handoff.ts, claudium_proxy.ts, and the client's src/net/stripe_checkout.ts); telemetry egress (server/parse/, especially shipper.ts); moderation and admin (admin.ts, admin_db.ts, moderation_db.ts, ip_block*.ts, content_moderation_db.ts); and the daily-rewards payout path (the daily_rewards*.ts modules plus the excluded-accounts moderation view). src/admin/ is in scope too. Always check any file the diff touches, whether or not it appears above.

The REST pipeline seam. New REST endpoints are RouteDef modules registered in server/http/registry.ts, never inline handlers in server/main.ts (the inline ladder is the retained legacy arm, kept for the API_DISPATCH=legacy rollback). For a migrated or new route, verify auth / ownership / rate limiting as DECLARED middleware and route meta, not in-handler code: require_account / require_admin / require_internal_secret / require_owned (an ownerScope 'account' denial is a 404 anti-enumeration response and MUST carry a loader; assertNoOwnedRouteShadowing in server/http/registry.ts guards the :id routes at build time), plus bearer_active_guard, origin_check, rate_limit, and turnstile under server/http/middleware/. Metric labels stay bounded (policy / kind / route TEMPLATE): never label with an ip, account, token, or concrete id. Read server/http/CLAUDE.md whenever the diff touches server/http/ or a routes-table file.

Read the full file on GitHub · 279 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 13d ago First seen · 279 lines · 68 tokens per session scan A 4c28a25b854c

Subscribe to this mod's changes

privacy-security-review is an agent published in the GitHub repository levy-street/world-of-claudecraft (2,251 stars, last pushed yesterday), licensed MIT. It adds 68 tokens to every session and 4,042 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other agents, from other repositories

technical-director

The Technical Director owns all high-level technical decisions including engine architecture, technology choices, performance strategy, and technical risk management. Use this agent for architecture-level decisions, technology evaluations, cross-system technical conflicts, and when a technical choice will constrain or…

Donchitos/Claude-Code-Game-Studios · 56 tokens

pixel-art-animation-reviewer

Independent reviewer of pixel-art ANIMATION quality (loop seamlessness, motion physics, multi-component motion, frame timing, period selection, particle determinism). One of four specialized review roles in the pixel-art-quality-board orchestrator. Use when the user asks to "check animation timing", "verify loop…

AnastasiyaW/codex-claude-code-config · 140 tokens

godot-game-dev

Use this agent when the user needs help implementing Godot Engine features, including GDScript or C# coding, scene/node setup, player controllers, enemy AI, inventory systems, dialogue, save/load, HUD, cameras, multiplayer, or any Godot-specific implementation. Examples: Context: User needs to implement enemy AI.…

jame581/GodotPrompter · 357 tokens

ai-programmer

Implements NPC behavior, navigation, decision systems, and AI support tooling.

MRCalderon3D/everything-game-dev-code · 19 tokens

game-engine-architect

Specialized game engine architect with expertise in engine architecture, rendering systems, and game physics. Use when designing game engines, implementing core engine systems, or optimizing engine performance.

TheBushidoCollective/han · 39 tokens

unity-ui-pro

Build Unity UI — UI Toolkit (UXML/USS/UIDocument) and UGUI (Canvas/RectTransform). Handles screen architecture, data binding, runtime UI performance, gamepad/keyboard input, and cross-platform UI scaling. Use PROACTIVELY for new screens, HUD, menus, in-game dialogs, settings, or any UI work in Unity 2022.3+. Not for…

AcKeskin/contexture · 102 tokens