Anti-Vibe Browser Cybersecurity Audit
Quality Assurance
163 checks · 20 sections
- [ ] Games are isolated from each other - [ ] One game cannot access another game’s files, secrets, storage, or runtime - [ ] Tenant IDs are enforced server-side - [ ] Cross-tenant data access is tested - [ ] Sandboxing boundaries are documented - [ ] Containers/VMs run with minimal privileges - [ ] No privileged containers unless absolutely necessary
- [ ] Uploaded game files are treated as untrusted - [ ] File type validation - [ ] Archive extraction protected against path traversal - [ ] Zip bombs/resource bombs handled - [ ] Malware scanning where appropriate - [ ] Build scripts run in isolated environments - [ ] Build jobs have CPU/memory/time limits - [ ] Build environments are destroyed after use - [ ] User builds cannot access host credentials - [ ] Build logs do not leak secrets
- [ ] User code cannot escape the sandbox - [ ] Runtime permissions are minimal - [ ] Filesystem access restricted - [ ] Network egress restricted where appropriate - [ ] Process spawning restricted - [ ] System calls restricted - [ ] Dangerous runtime APIs disabled where possible - [ ] Resource quotas enforced - [ ] Infinite loops cannot take down shared infrastructure
- [ ] HTTPS enforced - [ ] TLS certificates automatically renewed - [ ] Custom domain ownership verified - [ ] Subdomain takeover protections - [ ] Host header validation - [ ] Correct CORS behavior - [ ] Content Security Policy strategy - [ ] iframe/embed policies defined - [ ] Games cannot impersonate platform UI - [ ] Clear trust boundary between platform pages and hosted games
- [ ] Secure account login - [ ] MFA available - [ ] MFA required for admins - [ ] Session revocation - [ ] Secure password reset - [ ] OAuth callback URLs validated - [ ] Account linking protected - [ ] Brute-force protection - [ ] Suspicious login detection
- [ ] Platform secrets never exposed to games - [ ] User secrets encrypted - [ ] Secrets not visible in build logs - [ ] Secrets not embedded into frontend bundles accidentally - [ ] Secret access scoped per project/environment - [ ] Rotation supported - [ ] Secrets redacted in logs/errors - [ ] Temporary credentials preferred over permanent credentials
- [ ] Upload buckets are private by default - [ ] Signed URLs expire - [ ] Object keys cannot bypass authorization - [ ] Directory/path traversal blocked - [ ] Storage quotas enforced - [ ] Dangerous file types handled safely - [ ] Deleted games actually lose access to stored assets - [ ] Backups protected
- [ ] Tenant isolation in database layer - [ ] Parameterized queries - [ ] Connection pooling limits - [ ] Database credentials are not shared unnecessarily - [ ] Production databases are not internet-exposed - [ ] Row-level security where appropriate - [ ] Backups encrypted - [ ] Restore process tested
- [ ] Internal APIs require authentication - [ ] Service-to-service authorization - [ ] Least-privilege service identities - [ ] Metadata services protected - [ ] SSRF protections - [ ] Internal admin endpoints not publicly routable - [ ] Service discovery information is not exposed to tenants
- [ ] Network segmentation - [ ] Firewall rules reviewed - [ ] Default-deny where practical - [ ] Egress controls for untrusted workloads - [ ] Rate limits at edge - [ ] DDoS protection - [ ] CDN configured correctly - [ ] Origin servers protected from direct access where appropriate
- [ ] Users cannot host phishing pages unnoticed - [ ] Malware distribution controls - [ ] Crypto-mining/resource abuse detection - [ ] Bot hosting abuse considered - [ ] Spam hosting controls - [ ] Automated signup abuse controls - [ ] Per-account and per-project resource limits - [ ] Abuse reporting workflow - [ ] Fast takedown capability
- [ ] Domain ownership verification - [ ] DNS validation expires appropriately - [ ] Removed domains cannot remain attached - [ ] Certificate issuance authorization checked - [ ] Domain reuse does not expose prior tenant content - [ ] Dangling DNS records documented/warned about - [ ] Custom-domain redirects cannot create open redirects
- [ ] Deployments are immutable where practical - [ ] Previous versions retained safely - [ ] Rollback supported - [ ] Deployment artifacts have integrity checks - [ ] Production deploy permissions restricted - [ ] Environment separation: dev/staging/prod - [ ] Build provenance recorded - [ ] Dependency vulnerabilities scanned
- [ ] Admin panel isolated - [ ] MFA required - [ ] Admin actions audited - [ ] Support impersonation logged and restricted - [ ] No shared admin accounts - [ ] Production access is least-privilege - [ ] Break-glass access documented - [ ] Sensitive actions require re-authentication
- [ ] Security logs centralized - [ ] Authentication events logged - [ ] Permission changes logged - [ ] Deployments logged - [ ] Secret access logged where feasible - [ ] Cross-tenant access attempts detectable - [ ] Sandbox escapes/crashes alerted - [ ] Resource abuse alerted - [ ] Logs themselves are access-controlled
- [ ] Payment provider tokens never reach hosted games - [ ] Webhooks verified - [ ] Duplicate webhook handling - [ ] Subscription changes authorized - [ ] Usage metering cannot be manipulated by client requests - [ ] Billing admin actions audited
- [ ] Host OS patched - [ ] Runtime images patched - [ ] Base images pinned - [ ] Dependencies scanned - [ ] CI/CD permissions minimized - [ ] Build runners isolated - [ ] Artifact registry access controlled - [ ] Signing/provenance used where appropriate
- [ ] Compromised game can be disabled quickly - [ ] Compromised user sessions can be revoked - [ ] Individual tenants can be isolated - [ ] Secrets can be rotated quickly - [ ] Malicious deployments can be rolled back - [ ] Security contact exists - [ ] Incident runbooks exist - [ ] Post-incident audit trail available
- [ ] Upload a malicious archive and verify extraction is safe - [ ] Try accessing another project by changing its ID - [ ] Try reading platform environment variables from hosted code - [ ] Try making requests to internal infrastructure from a game - [ ] Exhaust CPU/memory in one tenant and verify others stay healthy - [ ] Try claiming another user's custom domain - [ ] Delete a project and verify its assets/secrets become inaccessible - [ ] Verify a compromised game cannot compromise the hosting control plane
01When to use
Use when reviewing a platform that uploads, builds, or hosts games from multiple users. Check the boundaries between untrusted game code, other tenants, and the hosting control plane, including domains, secrets, storage, and resource limits.