Agent fallback for CCSPlayer_MovementServices_ProcessMovement (auto-generated, category: func). Locate
CCSPlayer_MovementServices::ProcessMovement in the CS2 server module via IDA Pro MCP and emit a fresh,
minimal-unique artifact. The deterministic preprocessor could not resolve this
symbol on the current gamever - your job is the re-sign.
Trigger: CCSPlayer_MovementServices_ProcessMovement, CCSPlayer_MovementServices::ProcessMovement
Installs into .claude/skills of the current project.
Are you the author of Find CCSPlayer MovementServices ProcessMovement?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/mrc4tt-find-ccsplayer-movementservices-processmovement)
---
name: find-CCSPlayer_MovementServices_ProcessMovement
description: |
Agent fallback for CCSPlayer_MovementServices_ProcessMovement (auto-generated, category: func). Locate
CCSPlayer_MovementServices::ProcessMovement in the CS2 server module via IDA Pro MCP and emit a fresh,
minimal-unique artifact. The deterministic preprocessor could not resolve this
symbol on the current gamever - your job is the re-sign.
Trigger: CCSPlayer_MovementServices_ProcessMovement, CCSPlayer_MovementServices::ProcessMovement
disable-model-invocation: true
---
# Find CCSPlayer_MovementServices_ProcessMovement
Target: `CCSPlayer_MovementServices::ProcessMovement` (func) in the module loaded in THIS session.
> The old artifact/preprocessor anchors no longer match this build. Use anchors
> only to *locate* candidates; derive the artifact from the ACTUAL bytes you read.
> Produce ONLY this session's platform output. NEVER open another binary.
## ABI identification (mandatory)
`CCSPlayer_MovementServices::ProcessMovement(CMoveData*)` is **virtual**: on 14181 it is
vtable slot 29 (linux) / 28 (windows) of `CCSPlayer_MovementServices`. Accept only a candidate
that sits in that vtable. Head: linux `55 48 89 E5 41 57 41 56 41 55 49 89 F5 41 54 53 48 89 FB
48 83 EC ?? 48 8B 7F`, windows `40 57 41 57 48 81 EC ?? ?? ?? ?? 48 83 79`.
**Reject** the 14176–14181 candidate (linux `55 48 89 E5 41 57 49 89 FF 41 56 41 55 41 54 49 89 F4
53`, 14181 VA 0x1783c80 / windows RVA 0xc2a480): it is a non-virtual helper reached via the
`s_pRunCommandPawn` xref and is in no vtable. `uv run abi_guard.py` enforces this.
## Method
Locate via distinctive constants/strings in the body, cross-references from
known callers/callees, or the owning class vtable (RTTI) if virtual. Verify by
decompilation before committing to a candidate.
## Mandatory self-check before emitting
The pipeline re-reads the bytes at your `func_va` and regenerates `func_sig` from
them - a mismatch aborts the run. Therefore: read the real bytes via IDA MCP,
derive the artifact FROM those bytes (wildcard relocated operands as `??`), start
at the TRUE function head, and only then write the YAML. A mismatch is always a
bug in YOUR output.
## Output schema (STRICT)
Write `CCSPlayer_MovementServices_ProcessMovement.{platform}.yaml` with EXACTLY these fields:
```yaml
func_name: <TASK>
func_va: "<hex virtual address>"
func_rva: "<hex rva>"
func_size: "<hex size>"
func_sig: "<byte pattern, ?? wildcards, function head, minimal-unique>"
```
NEVER include vfunc_* or struct fields.
## Verification
1. Decompile and confirm the behavior matches the symbol's semantics.
2. Uniqueness: the pattern must match exactly ONE location in the loaded binary.
3. If no candidate can be confirmed, report the shortlist - a skipped symbol is
safer than a wrong signature.