Anti-Vibe Game Cybersecurity Audit
Quality Assurance
157 checks · 18 sections
- [ ] Never trust client-reported score, currency, XP, inventory, or damage - [ ] Server validates gameplay-critical actions - [ ] Client cannot directly grant itself items/rewards - [ ] Sensitive game logic is not enforced only client-side - [ ] Dev/debug commands disabled in production - [ ] Admin functionality cannot be exposed through the normal client
- [ ] Secure login flow - [ ] Session expiration - [ ] Token rotation where appropriate - [ ] Logout invalidates sessions - [ ] Password reset flow is protected - [ ] Brute-force protection - [ ] MFA for admin/dev accounts - [ ] No auth tokens in URLs or logs - [ ] Account linking cannot be hijacked
- [ ] Speed hacks detected/limited server-side - [ ] Teleport/movement sanity checks - [ ] Fire-rate/cooldown validation - [ ] Damage validation - [ ] Inventory mutation validation - [ ] Currency transactions validated - [ ] Impossible state transitions rejected - [ ] Replay/duplicate actions handled - [ ] Anti-cheat does not rely only on obfuscation - [ ] False-positive handling/process exists
- [ ] Purchases verified server-side - [ ] Receipt validation - [ ] Duplicate purchase protection - [ ] Currency cannot go negative unexpectedly - [ ] Trading is atomic - [ ] Item duplication prevented - [ ] Rollback/chargeback behavior defined - [ ] Marketplace price manipulation considered - [ ] Reward endpoints are idempotent
- [ ] TLS used for network traffic - [ ] No sensitive data sent in plaintext - [ ] Packet/message schema validated - [ ] Malformed packets rejected safely - [ ] Oversized payload protection - [ ] Rate limits per player/IP/device where appropriate - [ ] Reconnect flow cannot duplicate state - [ ] Replay attacks considered - [ ] Sequence/order handling where required - [ ] Disconnect abuse considered
- [ ] Input validation on every endpoint - [ ] Authentication required where expected - [ ] Authorization checked separately from authentication - [ ] Rate limiting - [ ] Request size limits - [ ] Pagination limits - [ ] No mass-assignment vulnerabilities - [ ] No internal/debug endpoints publicly exposed - [ ] Errors do not leak stack traces/secrets - [ ] API versions can be deprecated safely
- [ ] XSS protection - [ ] CSRF protection where relevant - [ ] Content Security Policy - [ ] Secure cookies - [ ] HttpOnly cookies where appropriate - [ ] SameSite configured appropriately - [ ] CORS is restrictive - [ ] No secrets embedded in frontend JavaScript - [ ] Third-party scripts audited - [ ] iframe/embed behavior controlled
- [ ] Chat input sanitized - [ ] Usernames/display names sanitized - [ ] Rich text/HTML restricted - [ ] File uploads validated - [ ] File type checked by content, not just extension - [ ] Upload size limits - [ ] Malicious URLs handled - [ ] Reporting/moderation tools exist - [ ] User-generated content cannot execute code
- [ ] Matchmaking endpoints rate-limited - [ ] Queue manipulation considered - [ ] Lobby spam prevented - [ ] Match result submission validated - [ ] Win/loss results cannot be spoofed - [ ] Spectator permissions checked - [ ] Private match codes are sufficiently random - [ ] Rejoining cannot duplicate rewards - [ ] Host migration abuse considered
- [ ] No API keys committed to client builds - [ ] Secrets stored in a secret manager - [ ] Credentials rotated - [ ] Separate dev/staging/prod credentials - [ ] Database is not publicly exposed - [ ] Internal services are network-restricted - [ ] Least-privilege service accounts - [ ] Cloud storage permissions audited - [ ] Backups access-controlled
- [ ] Parameterized queries - [ ] SQL/NoSQL injection protection - [ ] Least-privilege DB accounts - [ ] Sensitive fields encrypted where needed - [ ] Player data access logged where appropriate - [ ] Admin queries cannot accidentally target all users - [ ] Backup restore tested - [ ] Data deletion works correctly
- [ ] Connection rate limiting - [ ] Login throttling - [ ] Expensive endpoints protected - [ ] Match creation limits - [ ] Chat/message flood protection - [ ] Bot abuse considered - [ ] Graceful degradation under attack - [ ] DDoS protection/CDN configured where relevant
- [ ] Dependencies regularly updated - [ ] Known vulnerabilities scanned - [ ] Lockfiles committed - [ ] CI secrets protected - [ ] Production builds reproducible where practical - [ ] Build artifacts signed where appropriate - [ ] Third-party SDKs reviewed - [ ] Removed unused SDKs/plugins - [ ] Mod/plugin boundaries sandboxed where possible
- [ ] Collect only necessary player data - [ ] Sensitive data encrypted in transit - [ ] Sensitive data encrypted at rest where appropriate - [ ] Logs avoid passwords/tokens/payment data - [ ] Account deletion works - [ ] Data retention rules defined - [ ] Children's data requirements considered where applicable - [ ] Analytics does not expose private player data
- [ ] Admin panel protected by MFA - [ ] Admin actions logged - [ ] Privileged actions require authorization - [ ] Ban/unban actions audited - [ ] No shared admin accounts - [ ] Production console access restricted - [ ] Dangerous actions require confirmation - [ ] Emergency access process exists
- [ ] Security logs centralized - [ ] Suspicious login alerts - [ ] Economy anomalies detectable - [ ] Cheat spikes detectable - [ ] Token revocation available - [ ] Compromised accounts can be locked - [ ] Incident response playbook - [ ] Security contact/reporting channel - [ ] Rollback strategy after exploit discovery
- [ ] Modify client-side currency and see if server accepts it - [ ] Replay the same reward request twice - [ ] Change another player's ID in API requests - [ ] Spam actions faster than gameplay should allow - [ ] Send malformed or missing fields - [ ] Disconnect during purchases/trades/rewards - [ ] Reconnect repeatedly during a match - [ ] Attempt requests without authentication - [ ] Attempt admin endpoints as a normal player - [ ] Verify exploits fail safely without corrupting player state
01When to use
Use to review the security of a game with accounts, multiplayer, rewards, purchases, or player-generated content. Focus on server authority, permissions, economy integrity, abuse paths, and safe recovery from attempted exploits.