本文へ移動
cccskills
無料GitHub で公開

find-CBaseEntity_SpawnRadius

Find and identify the CBaseEntity_SpawnRadius function in the CS2 server binary using IDA Pro MCP. Use this skill when reverse engineering CS2 server.dll or libserver.so to locate the radius-aware spawn helper that resolves an entity's effect/trigger radius from either its float argument or the "radius" keyvalue, then applies it and reads the entity's "hammerUniqueId" keyvalue. Resolved via the two econ/ hammer keyvalue literals "radius" and "hammerUniqueId": the single function that references BOTH is the target. Trigger: CBaseEntity_SpawnRadius, SpawnRadius

インストール方法を見る

含まれるファイル(1)

  • SKILL.md4.8 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Find CBaseEntity_SpawnRadius

Locate CBaseEntity_SpawnRadius in CS2 server.dll / libserver.so using IDA Pro MCP tools.

This is a non-virtual, direct-call member function (no vtable entry of its own — emit a byte sig, not an offset).

Do not anchor the discovery recipe on the raw byte pattern below — bytes/wildcards shift release to release. Use it only to locate/confirm the function on the currently loaded binary, then generate a fresh signature at the end.

Method

1. Locate the durable anchor string

CBaseEntity_SpawnRadius reads two entity keyvalues by name — "radius" and "hammerUniqueId". The "hammerUniqueId" literal is the rarer, more distinctive anchor (a single string in the module).

mcp__ida-pro-mcp__find   type="string" targets=["hammerUniqueId"]

Linux 14168 reference: "hammerUniqueId" is at 0x92a4b9.

2. Shortlist the referencing functions

mcp__ida-pro-mcp__xrefs_to   addrs="0x92a4b9"

"hammerUniqueId" is referenced by a small handful of functions (its keyvalue lookup appears at the tail of several spawn/precache-style routines).

Linux 14168 reference: referenced by three functions — sub_D4AB10 (0xD4AB10, size 0x4bd), sub_16BFA90 (0x16BFA90), and sub_181F580 (0x181F580).

3. Disambiguate with the "radius" keyvalue

CBaseEntity_SpawnRadius is the only one of those functions that also references the "radius" keyvalue string. Decompile each candidate and keep the one that references both "radius" and "hammerUniqueId":

mcp__ida-pro-mcp__decompile   addr="<candidate_func_va>"

The target's body has this distinctive shape:

  • Signature (entity *this, KeyValues *pKV, float radius) — takes a float radius argument.
  • When the float argument is negative, it falls back to reading the "radius" keyvalue by name (via the keyvalue-by-name lookup helper) and coerces the result (int/uint64/double/string) to a float.
  • If the resolved radius is > 0.0, it applies it to the entity's collision/trigger bounds structure; otherwise it takes the zero-radius path.
  • Near the end it reads the "hammerUniqueId" keyvalue and stores the resulting string on the entity.

Linux 14168 reference: the target is sub_D4AB10 at 0xD4AB10. It reads "radius" (0x90068f) in the a3 < 0.0 branch and "hammerUniqueId" (0x92a4b9) near the end. The other two candidates reference only "hammerUniqueId".

4. Generate function signature

ALWAYS Use SKILL /generate-signature-for-function with addr=<target_func_va> to generate a robust and unique func_sig.

Linux 14168 reference: 55 48 89 E5 41 57 41 56 41 55 41 54 49 89 F4 53 48 89 FB 48 83 EC 68 F3 0F 11 85 7C FF FF FF — unique across the binary at this length (no wildcards required).

5. Write IDA Analysis Output as YAML

ALWAYS Use SKILL /write-func-as-yaml to write the analysis results.

Required parameters:

  • func_name: CBaseEntity_SpawnRadius
  • func_addr: <target_func_va>
  • func_sig: The validated signature from step 4

Function Characteristics

  • Purpose: Resolves an entity's radius (from a float argument, or the "radius" keyvalue when the argument is negative), applies it to the entity's bounds/collision, and reads the "hammerUniqueId" keyvalue.
  • Binary: server.dll / libserver.so
  • Linkage: non-virtual, direct-call (no vtable entry).
  • Parameters: (__int64 this, __int64 pKeyValues, float radius) (observed decompiled shape).
  • Return value: non-void (propagates an allocation/cleanup result).

Discovery Strategy

  1. Anchor on the rare literal "hammerUniqueId" and take its (few) referencers.
  2. Intersect with the "radius" keyvalue literal — exactly one referencer uses both.
  3. Confirm the candidate takes a float radius argument and has the negative-argument → "radius" keyvalue fallback body shape.

This is robust because both anchors are verbatim keyvalue-name literals that survive recompilation, and the two-string intersection is unambiguous.

Output YAML Format

func_name: CBaseEntity_SpawnRadius
func_va: '0x<va>'
func_rva: '0x<rva>'
func_size: '0x<size>'
func_sig: <space-separated byte pattern from step 4>

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Clean up the local workspace after a dev branch has been merged into main. Verifies the current dev branch is fully merged into origin/main, then switches to main, pulls the latest, deletes the local dev branch, and deletes the remote dev branch if it still exists. STOPS and warns the user if the current branch is not yet merged. Triggers: cleanup workspace, cleanup branch, delete merged branch, finish dev branch, post-merge cleanup

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

Convert an existing find-XXXX SKILL.md into a preprocessor Python script, updating configs/<GAMEVER>.yaml and removing the old SKILL.md. Covers xref-string-based and LLM_DECOMPILE-based discovery patterns.

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

Create an Agent SKILL.md fallback for an existing find-XXXX finder that relies on a fragile discovery foundation — above all LLM_DECOMPILE (patterns C/D/E), which matches the decompiled shape of a predecessor function against a stored reference and breaks when a symbol is inlined or de-inlined in a way the reference does not cover. The generated fallback coexists with the preprocessor and runs only when it returns failure, recovering every target robustly by decompiling the predecessor and following the inline/de-inline boundary with semantic anchors. Use when a finder broke on a game update, or you want to durably backstop one before it does. The recipe generalizes to any finder foundation. Triggers: create agent skill fallback, add SKILL.md fallback, robust fallback for finder, backstop LLM_DECOMPILE finder, final guarantee skill

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

Create a new cpp_tests entry for validating a C++ interface vtable layout against binary reference YAMLs. Creates the .cpp test file in cpp_tests/ and appends a configs/<GAMEVER>.yaml entry under cpp_tests:. Use when a user asks to add vtable layout validation for a new hl2sdk_cs2 interface class.

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

create-pr

無料

Create a GitHub pull request from staged task changes or an already-committed current branch. Deliver source/config/ reference changes together with their computed source-owned `bin_artifacts` closure. PR validation routing is owned by the default-branch trusted workflow; snapshots, gamedata, and manifests are Release-derived only.

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

Create a new find-XXXX preprocessor Python script from scratch (no existing SKILL.md), add configs/<GAMEVER>.yaml skill and symbol entries. Covers xref-string-based and LLM_DECOMPILE-based discovery patterns. Use when a GitHub issue or user instruction specifies a new function to find.

日本語の概要は準備中です。原文の説明を表示しています。

mrc4tt/CS2_VibeSignatures32026年10月10日 更新

mrc4tt のスキルをすべて見る

このスキルの問題を報告する