Borrowing it
Nothing to install: this file belongs to HLND2T/CS2_VibeSignatures. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/HLND2T/CS2_VibeSignatures/main/.claude/skills/find-CNetworkMessages_vtable-decompiles/SKILL.mdgit clone --depth 1 https://github.com/HLND2T/CS2_VibeSignaturesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hlnd2t/cs2_vibesignatures/find-cnetworkmessages_vtable-decompiles)<a href="https://agentmods.dev/skills/hlnd2t/cs2_vibesignatures/find-cnetworkmessages_vtable-decompiles"><img src="https://agentmods.dev/badge/skills/hlnd2t/cs2_vibesignatures/find-cnetworkmessages_vtable-decompiles/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hlnd2t/cs2_vibesignatures/find-cnetworkmessages_vtable-decompiles"><img src="https://agentmods.dev/badge/skills/hlnd2t/cs2_vibesignatures/find-cnetworkmessages_vtable-decompiles.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00114 | $0.01687 |
| Opus 5 | $0.00057 | $0.00843 |
| Sonnet 5 | $0.00023 | $0.00337 |
| Haiku 4.5 | $0.00011 | $0.00169 |
Grade A, and why
find-CNetworkMessages_vtable-decompiles scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 176 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Find CNetworkMessages_AllowAdditionalMessageRegistration and CNetworkMessages_IsAdditionalMessageRegistrationAllowed
Locate CNetworkMessages_AllowAdditionalMessageRegistration and CNetworkMessages_IsAdditionalMessageRegistrationAllowed vfuncs in CS2 networksystem.dll or libnetworksystem.so using IDA Pro MCP tools.
Method
1. Load CNetworkMessages_RegisterNetworkFieldChangeCallbackInternal from YAML
ALWAYS Use SKILL /get-func-from-yaml with func_name=CNetworkMessages_RegisterNetworkFieldChangeCallbackInternal.
If the skill returns an error, STOP and report to user.
Otherwise, extract:
vfunc_indexofCNetworkMessages_RegisterNetworkFieldChangeCallbackInternalvfunc_offsetofCNetworkMessages_RegisterNetworkFieldChangeCallbackInternal
2. Load CNetworkMessages VTable from YAML
ALWAYS Use SKILL /get-vtable-from-yaml with class_name=CNetworkMessages.
If the skill returns an error, STOP and report to user.
Otherwise, extract:
vtable_numvfuncvtable_entries
3. Resolve the Two Adjacent Slots
Compute the candidate slots:
allow_vfunc_index = CNetworkMessages_RegisterNetworkFieldChangeCallbackInternal.vfunc_index + 1allow_vfunc_offset = CNetworkMessages_RegisterNetworkFieldChangeCallbackInternal.vfunc_offset + 8isallowed_vfunc_index = CNetworkMessages_RegisterNetworkFieldChangeCallbackInternal.vfunc_index + 2isallowed_vfunc_offset = CNetworkMessages_RegisterNetworkFieldChangeCallbackInternal.vfunc_offset + 16
Validate that isallowed_vfunc_index < vtable_numvfunc, then read:
allow_func_addr = CNetworkMessages_vtable[allow_vfunc_index]isallowed_func_addr = CNetworkMessages_vtable[isallowed_vfunc_index]
This adjacent-slot rule is required because AllowAdditionalMessageRegistration and IsAdditionalMessageRegistrationAllowed immediately follow RegisterNetworkFieldChangeCallbackInternal in the CNetworkMessages vtable.
4. Decompile Both Candidate Functions
Decompile both candidates:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 176 lines · 114 tokens per session scan A 1695c0400fda
find-CNetworkMessages_vtable-decompiles is a skill published in the GitHub repository HLND2T/CS2_VibeSignatures (65 stars, last pushed yesterday), licensed MIT. It adds 114 tokens to every session and 1,687 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
minecraft-debug-mcp
Operate and debug the live Minecraft bot through its built-in MCP REPL server. Use when work requires starting the bot with pnpm dev, connecting to the local MCP endpoint, inspecting cognitive state/logs/history, injecting synthetic chat/events, or running targeted REPL code against the running brain during…
graphics-api-hooking
Analyze Direct3D/DXGI, OpenGL, and Vulkan rendering, presentation, composition, and capture evidence. Use to distinguish API samples, PresentMon event metrics, Tracy instrumentation, compatibility translation, frame images, and validation diagnostics; review swap chains, overlays, resource lifetime, and…
console-get-logs
Retrieve Unity Editor logs from the MCP plugin's LogCollector, optionally filtered by log type or time window. Useful for debugging and monitoring Editor activity.
editor-application-get-state
Return the current state of UnityEditor.EditorApplication — playmode, paused state, compilation state, and related flags.
console-clear-logs
Clear the MCP log cache (used by 'console-get-logs') and the Unity Editor Console window. Useful for isolating logs to a specific action by clearing the slate first.
profiler-start
Enable Unity's runtime profiler and open the Profiler window. Idempotent: calling when already enabled returns the current enabled state without error.