Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add SummerEngine/summer-engine-agent --skill host-authoritative-stategit clone --depth 1 https://github.com/SummerEngine/summer-engine-agentWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/summerengine/summer-engine-agent/host-authoritative-state)<a href="https://agentmods.dev/skills/summerengine/summer-engine-agent/host-authoritative-state"><img src="https://agentmods.dev/badge/skills/summerengine/summer-engine-agent/host-authoritative-state/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/summerengine/summer-engine-agent/host-authoritative-state"><img src="https://agentmods.dev/badge/skills/summerengine/summer-engine-agent/host-authoritative-state.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00074 | $0.04386 |
| Opus 5 | $0.00037 | $0.02193 |
| Sonnet 5 | $0.00015 | $0.00877 |
| Haiku 4.5 | $0.00007 | $0.00439 |
Grade A, and why
host-authoritative-state scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- host-authoritative-state — 89% identical, 18 lines differ
How it starts
The opening of the file, as written. The whole thing — 333 lines — stays where its author put it; the contents beside it link to each section on GitHub.
/host-authoritative-state — Designing the State Layer
Overview
This is Layer 2 of multiplayer architecture. /peer-to-peer-multiplayer covers all four layers; this skill zooms in on the one that produces 90% of shipping-quality MP bugs. For every piece of state in your game, decide: does the host own it, or does the client own it? Get this wrong and you ship a cheat-vulnerable, desync-prone game where players "teleport," items dupe, and hit-detection lies. Get it right and the rest of multiplayer falls into place.
The fundamental question
For every state field, ask one question:
If a malicious client lies about this, does it break the game?
| Answer | Owner | Notes |
|---|---|---|
| Yes | Host-authoritative. | Clients send intent (RPC request); host validates and broadcasts. |
| No | Client-owned. | Cosmetic. Replicated for visual sync only. |
| Sometimes | Host-authoritative with client prediction. | Position is the canonical example: client predicts to feel responsive; host reconciles to prevent teleport-cheats. |
This question is the entire decision tree. Apply it to every field, no exceptions.
The decision matrix
The canonical state-ownership table for a typical 3D action game. Use this as your starting point and extend per game.
| State field | Owner | Why | What an attacker could do if you got it wrong |
|---|---|---|---|
health |
host | core combat integrity | edit memory → infinite HP, ignore damage |
mana / stamina |
host | gates ability/sprint use | infinite-cast spam, infinite-sprint |
score / kills / objectives |
host | competitive integrity | self-award kills, fake leaderboard |
inventory contents |
host | items must not dupe | broadcast "I picked it up" twice → duped item |
currency (gold, gems) |
host | trade exploits | mint currency on the client |
ability_cooldowns |
host | gates damage rate | spam-cast every frame |
current_weapon equipped |
host | tied to inventory and damage tables | swap to "best gun" without owning it |
team_assignment |
host | balance + friendly fire | switch sides mid-match |
ready_state (lobby) |
host | match-start gating | force-start with one player |
chat_messages |
host-relayed | moderation hooks, profanity filter | bypass mute, broadcast to muted peers |
position |
client-predicted, host-reconciled | input latency feels awful otherwise | speed-hack, teleport — reconciliation catches both |
velocity |
client-predicted, host-reconciled | same as position | same as position |
look_direction (yaw/pitch) |
client | cosmetic; host doesn't need it for hit-reg if you raycast on host | cheating here doesn't help |
animation_state |
client | visual; can lead the truth | wrong anim = visual glitch, not exploit |
footstep_audio |
client | host doesn't care | spam → mild annoyance, not exploit |
particle_fx / muzzle_flash |
client | host doesn't care | same |
aim_assist_target |
client | local UX | spoofing it only hurts the spoofer |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago Changed · +74 tokens per session 2ba402ba2936
- 11d ago First seen · 333 lines · 0 tokens per session scan A 8b7eda9b52c8
host-authoritative-state is a skill published in the GitHub repository SummerEngine/summer-engine-agent (59 stars, last pushed today), licensed MIT. It adds 74 tokens to every session and 4,386 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
self-evolve
Capture reusable patterns from a finished project and lift them into framework-level priors (contracts, modules, skeletons) that future projects inherit. Run only when the user explicitly requests self-evolution; the orchestrator executes the workflow.
artist-self-evolve
Distill stable art-generation patterns from a completed project, so future projects produce comparable assets without re-discovering the prompts. Lead-dispatched only — orchestrator invokes this skill from its self-evolve flow with a game-slug message; do not self-trigger.
vibegame-build
Run VibeGame's standard end-to-end game development workflow with reviewer gates. Use when the user wants to create a game from zero or evolve an existing game across multiple stages.
vibegame-start
Resume a VibeGame orchestrator session after vibegame start. Use at the beginning of a Claude or Codex session to inspect team runtime state, repair missing persistent members, load goal and GDD context, inspect tasks, and ask the user what to do next.
vibegame-edit
Iterate broadly on an existing game, on top of vibegame-build. Use when the user asks to change an existing game's art style, genre, or core rules. Not for local tuning such as numbers or game feel. Orchestrator only.
hearth-art
Give a Hearth game real art and sound — importing and slicing spritesheets, animations, procedural sprites and sounds, autonomous CC0 asset sourcing (Kenney, itch.io, OpenGameArt, Freesound, Google Fonts) with licensing rules, and pixel-art discipline (never stretch; read the art before using it). Use when the game…