Install
$ agentstack add skill-hlnd2t-cs2-vibesignatures-find-ccsplayer-movementservices-fullwalkmove-speedclamp ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
CCSPlayerMovementServicesFullWalkMove_SpeedClamp Patch Workflow
Overview
Locate the velocity clamping branch inside CCSPlayer_MovementServices_FullWalkMove and generate a patch that converts the conditional jump into an unconditional jump, making the speed-clamp code a dead path.
The target code pattern in pseudocode:
v20 = (float)((float)(v16 * v16) + (float)(v19 * v19)) + (float)(v17 * v17);
if ( v20 > (float)(v18 * v18) ) // ")
In the decompiled output, search for the velocity clamping pattern. The key indicators are:
- A sum-of-squares computation:
(x*x) + (y*y) + (z*z)stored in a variable (e.g.,v20) - Compared against another float squared:
v20 > (float)(v18 * v18) - Inside the if-block:
fsqrt, division, and writes toa2+56,a2+60,a2+64(velocity vector)
Note the address annotation on the comparison line (e.g., /*0x180a00e28*/ or similar).
3. Disassemble Around the Comparison
Disassemble the function starting from slightly before the annotated address to find the exact comiss + jbe/jbe short instruction pair:
mcp__ida-pro-mcp__disasm(addr="", offset=, max_instructions=30)
Look for this assembly pattern:
addss xmm2, xmm1 ; v20 = sum of squares
comiss xmm2, xmm0 ; compare v20 vs v18*v18
jbe loc_XXXXXXXX ; skip clamp block if v20 ", "size": 6})
Determine the patch based on the instruction encoding:
Case A: Near jbe (0F 86 rel32 — 6 bytes)
patch_bytes=E9 90- Compute:
new_rel32 = jump_target - (patch_va + 5)
Case B: Short jbe (76 rel8 — 2 bytes)
patch_bytes=EB- The
rel8stays the same (same target,jmp shortuses same displacement encoding asjbe short)
5. Generate Patch Signature
ALWAYS Use SKILL /generate-signature-for-patch to generate and validate the signature.
Required context for the skill:
func_name:CCSPlayer_MovementServices_FullWalkMovefunc_va: From step 1patch_va: Address of thejbeinstruction from step 3original_instruction: e.g.,jbe loc_180A00EE4patched_instruction: e.g.,jmp loc_180A00EE4description:Disable velocity clamping in FullWalkMove - patch conditional jbe to unconditional jmp to skip the speed clamping if-branch
6. Write YAML Output
ALWAYS Use SKILL /write-patch-as-yaml to persist the results.
Required parameters:
patch_name:CCSPlayer_MovementServices_FullWalkMove_SpeedClamppatch_sig: The validated signature from step 5patch_bytes: The computed patch bytes from step 4patch_sig_disp: From step 5 result (omit if 0)
Output YAML Files
CCSPlayer_MovementServices_FullWalkMove_SpeedClamp.windows.yamlCCSPlayer_MovementServices_FullWalkMove_SpeedClamp.linux.yaml
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: HLND2T
- Source: HLND2T/CS2_VibeSignatures
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.