host-authoritative-state

host-authoritative-state is a skill for Claude Code from SummerEngine/summer-engine-agent. It costs 74 tokens per session (4,386 once invoked), scanned A, original, MIT.

A design guide for deciding who controls each piece of game data in a multiplayer Summer game: the host or a connected player. The host is the central game instance that validates requests and shares the accepted results.

In plain words
What is it for?
Use it to decide which data clients may control, which changes the host must validate, and where client prediction may be reconciled by the host.
Why use it?
Clear ownership helps prevent cheating, duplicated items, incorrect hit detection, and players seeing different versions of the game state.

Skill for Claude Code

Written for Claude Code: allowed-tools in frontmatter. Also seen: mentions Claude Code; mentions Codex.

Part of the summer plugin — 80 skills, 2 commands, 2 hooks, 1 MCP server shipped together

Good fit Use it to decide which data clients may control, which changes the host must validate, and where client prediction may be reconciled by the host.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/summerengine/summer-engine-agent/host-authoritative-state
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add SummerEngine/summer-engine-agent --skill host-authoritative-state
Clone the repo
git clone --depth 1 https://github.com/SummerEngine/summer-engine-agent

Made for: Claude Code.

Or install summer, the plugin that ships this one along with the rest of its 80 skills, 2 commands, 2 hooks, 1 MCP server.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for host-authoritative-state

README.md
[![agentmods](https://agentmods.dev/badge/skills/summerengine/summer-engine-agent/host-authoritative-state/github.svg)](https://agentmods.dev/skills/summerengine/summer-engine-agent/host-authoritative-state)
Your own site
<a href="https://agentmods.dev/skills/summerengine/summer-engine-agent/host-authoritative-state"><img src="https://agentmods.dev/badge/skills/summerengine/summer-engine-agent/host-authoritative-state/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for host-authoritative-state

Your own site · 80×15
<a href="https://agentmods.dev/skills/summerengine/summer-engine-agent/host-authoritative-state"><img src="https://agentmods.dev/badge/skills/summerengine/summer-engine-agent/host-authoritative-state.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 74 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,386 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00074 $0.04386
Opus 5 $0.00037 $0.02193
Sonnet 5 $0.00015 $0.00877
Haiku 4.5 $0.00007 $0.00439

Measured 7d ago against content hash 2ba402ba2936, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

host-authoritative-state scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

skills/multiplayer-and-networking/host-authoritative-state/SKILL.md · 333 lines

How it starts

The opening of the file, as written. The whole thing — 333 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/host-authoritative-state — Designing the State Layer

Overview

This is Layer 2 of multiplayer architecture. /peer-to-peer-multiplayer covers all four layers; this skill zooms in on the one that produces 90% of shipping-quality MP bugs. For every piece of state in your game, decide: does the host own it, or does the client own it? Get this wrong and you ship a cheat-vulnerable, desync-prone game where players "teleport," items dupe, and hit-detection lies. Get it right and the rest of multiplayer falls into place.

The fundamental question

For every state field, ask one question:

If a malicious client lies about this, does it break the game?

Answer Owner Notes
Yes Host-authoritative. Clients send intent (RPC request); host validates and broadcasts.
No Client-owned. Cosmetic. Replicated for visual sync only.
Sometimes Host-authoritative with client prediction. Position is the canonical example: client predicts to feel responsive; host reconciles to prevent teleport-cheats.

This question is the entire decision tree. Apply it to every field, no exceptions.

The decision matrix

The canonical state-ownership table for a typical 3D action game. Use this as your starting point and extend per game.

State field Owner Why What an attacker could do if you got it wrong
health host core combat integrity edit memory → infinite HP, ignore damage
mana / stamina host gates ability/sprint use infinite-cast spam, infinite-sprint
score / kills / objectives host competitive integrity self-award kills, fake leaderboard
inventory contents host items must not dupe broadcast "I picked it up" twice → duped item
currency (gold, gems) host trade exploits mint currency on the client
ability_cooldowns host gates damage rate spam-cast every frame
current_weapon equipped host tied to inventory and damage tables swap to "best gun" without owning it
team_assignment host balance + friendly fire switch sides mid-match
ready_state (lobby) host match-start gating force-start with one player
chat_messages host-relayed moderation hooks, profanity filter bypass mute, broadcast to muted peers
position client-predicted, host-reconciled input latency feels awful otherwise speed-hack, teleport — reconciliation catches both
velocity client-predicted, host-reconciled same as position same as position
look_direction (yaw/pitch) client cosmetic; host doesn't need it for hit-reg if you raycast on host cheating here doesn't help
animation_state client visual; can lead the truth wrong anim = visual glitch, not exploit
footstep_audio client host doesn't care spam → mild annoyance, not exploit
particle_fx / muzzle_flash client host doesn't care same
aim_assist_target client local UX spoofing it only hurts the spoofer

Read the full file on GitHub · 333 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 7d ago Changed · +74 tokens per session 2ba402ba2936
  2. 11d ago First seen · 333 lines · 0 tokens per session scan A 8b7eda9b52c8

Subscribe to this mod's changes

host-authoritative-state is a skill published in the GitHub repository SummerEngine/summer-engine-agent (59 stars, last pushed today), licensed MIT. It adds 74 tokens to every session and 4,386 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

self-evolve

Capture reusable patterns from a finished project and lift them into framework-level priors (contracts, modules, skeletons) that future projects inherit. Run only when the user explicitly requests self-evolution; the orchestrator executes the workflow.

tettethu/VibeGame · 50 tokens

artist-self-evolve

Distill stable art-generation patterns from a completed project, so future projects produce comparable assets without re-discovering the prompts. Lead-dispatched only — orchestrator invokes this skill from its self-evolve flow with a game-slug message; do not self-trigger.

tettethu/VibeGame · 62 tokens

vibegame-build

Run VibeGame's standard end-to-end game development workflow with reviewer gates. Use when the user wants to create a game from zero or evolve an existing game across multiple stages.

tettethu/VibeGame · 42 tokens

vibegame-start

Resume a VibeGame orchestrator session after vibegame start. Use at the beginning of a Claude or Codex session to inspect team runtime state, repair missing persistent members, load goal and GDD context, inspect tasks, and ask the user what to do next.

tettethu/VibeGame · 61 tokens

vibegame-edit

Iterate broadly on an existing game, on top of vibegame-build. Use when the user asks to change an existing game's art style, genre, or core rules. Not for local tuning such as numbers or game feel. Orchestrator only.

tettethu/VibeGame · 57 tokens

hearth-art

Give a Hearth game real art and sound — importing and slicing spritesheets, animations, procedural sprites and sounds, autonomous CC0 asset sourcing (Kenney, itch.io, OpenGameArt, Freesound, Google Fonts) with licensing rules, and pixel-art discipline (never stretch; read the art before using it). Use when the game…

echoo19/hearth · 89 tokens