Borrowing it
Nothing to install: this file belongs to HLND2T/CS2_VibeSignatures. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/HLND2T/CS2_VibeSignatures/main/.claude/skills/run-vcall-finder/SKILL.mdgit clone --depth 1 https://github.com/HLND2T/CS2_VibeSignaturesWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hlnd2t/cs2_vibesignatures/run-vcall-finder)<a href="https://agentmods.dev/skills/hlnd2t/cs2_vibesignatures/run-vcall-finder"><img src="https://agentmods.dev/badge/skills/hlnd2t/cs2_vibesignatures/run-vcall-finder/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hlnd2t/cs2_vibesignatures/run-vcall-finder"><img src="https://agentmods.dev/badge/skills/hlnd2t/cs2_vibesignatures/run-vcall-finder.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00051 | $0.00594 |
| Opus 5 | $0.00026 | $0.00297 |
| Sonnet 5 | $0.00010 | $0.00119 |
| Haiku 4.5 | $0.00005 | $0.00059 |
Grade A, and why
run-vcall-finder scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 54 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Run VCall Finder
Run ida_analyze_bin.py with an explicit module list and symbol list. Never add vcall_finder entries to an analysis
config, use *, or infer additional modules or symbols.
Resolve Inputs
- Require one or more exact module names and one or more exact symbol names from the user. Ask for missing or ambiguous values before running the workflow.
- Use the exact
GAMEVERfrom the request. If omitted, readCS2VIBE_GAMEVERfrom.env; ask if it is absent or empty. Do not substitute another version. - Use the requested platform list. If omitted, allow the analyzer default of
windows,linux. - Require
configs/<GAMEVER>.yamland the selected binaries underbin/<GAMEVER>. Do not modify the config or download missing binaries as part of this skill.
Run The Analysis
Run from the repository root. Join multiple modules and symbols with commas:
uv run ida_analyze_bin.py -gamever <GAMEVER> -configyaml configs/<GAMEVER>.yaml -modules <MODULES> -vcall_finder <SYMBOLS> -debug
Add -platform <PLATFORMS> only when the user specifies platforms. Forward user-requested -llm_model,
-llm_baseurl, -llm_temperature, -llm_effort, or -llm_fake_as values. Prefer CS2VIBE_LLM_* environment
variables for credentials and never print or persist API keys.
Do not add -skip_error unless the user explicitly requests best-effort processing. Do not silently retry with other
modules, symbols, platforms, game versions, or cached detail files.
The analyzer applies every requested symbol to every requested module. Split the work into separate invocations when different symbols require different module scopes.
Report Results
Treat exit code 0 with Failed: 0 in the final summary as success. Report:
- the exact game version, modules, symbols, and platforms;
- the per-function detail root at
vcall_finder/<GAMEVER>/<SYMBOL>/; - the aggregated output at
vcall_finder/<GAMEVER>/<SYMBOL>.txtwhen produced.
If the command fails, report its exit code and relevant final error or summary lines inside:
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 54 lines · 51 tokens per session scan A ac5e9a7607b3
run-vcall-finder is a skill published in the GitHub repository HLND2T/CS2_VibeSignatures (65 stars, last pushed yesterday), licensed MIT. It adds 51 tokens to every session and 594 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
minecraft-debug-mcp
Operate and debug the live Minecraft bot through its built-in MCP REPL server. Use when work requires starting the bot with pnpm dev, connecting to the local MCP endpoint, inspecting cognitive state/logs/history, injecting synthetic chat/events, or running targeted REPL code against the running brain during…
graphics-api-hooking
Analyze Direct3D/DXGI, OpenGL, and Vulkan rendering, presentation, composition, and capture evidence. Use to distinguish API samples, PresentMon event metrics, Tracy instrumentation, compatibility translation, frame images, and validation diagnostics; review swap chains, overlays, resource lifetime, and…
console-get-logs
Retrieve Unity Editor logs from the MCP plugin's LogCollector, optionally filtered by log type or time window. Useful for debugging and monitoring Editor activity.
editor-application-get-state
Return the current state of UnityEditor.EditorApplication — playmode, paused state, compilation state, and related flags.
console-clear-logs
Clear the MCP log cache (used by 'console-get-logs') and the Unity Editor Console window. Useful for isolating logs to a specific action by clearing the slate first.
profiler-start
Enable Unity's runtime profiler and open the Profiler window. Idempotent: calling when already enabled returns the current enabled state without error.