Roblox security
Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.From its SKILL.md
npx -y skills add TabooHarmony/roblox-brain --skill roblox-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
2.9 KB, 510 tokens by cl100k_base, as published. Nobody here has run it
Roblox Security
When to Load
Load for exploit audits and hardening. Covers classic replication, opt-in Server Authority, remote abuse, economy attacks, and DataStore flows. Use roblox-networking for validation and rate-limit implementations.
Quick Reference
Core: Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.
Authority Models
- Classic replication: validate client requests and custom movement against server state. Never trust client damage, currency, inventory, permissions, or positions.
- Server Authority: with
Workspace.AuthorityMode = Serverand its required settings, the server owns core simulation while clients predict and recover from misprediction. UseBindToSimulation()(requiresWorkspace.UseFixedSimulationenabled in Studio), not blanketHeartbeatCFrame correction. - Both: validate attacks, purchases, teleports, dashes, permissions, and custom remotes at the server boundary.
Vectors & Mitigations
| Vector | Attack | Fix |
|---|---|---|
| Movement | Custom dash, teleport, or locomotion abuse | Server state and transition checks; under Server Authority, keep simulation logic in BindToSimulation() (requires Workspace.UseFixedSimulation enabled in Studio) and do not add blanket CFrame snap-back |
| Remote | Spam, arg spoof, replay | Rate limiter + validate arg types + idempotency |
| Economy | Dupe, negative qty | Session lock, atomic ops, qty > 0 |
| DataStore | Save spam, session hijack | Server-controlled saves, maintained session ownership protocol |
| General | Client trusts values | Server computes ALL game state |
Audit Checklist
CRITICAL: Server-authoritative state · Choose and document the authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client or replicated code
HIGH: Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects
MEDIUM: Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering
Anti-Patterns
Don't obfuscate client code, use _G for security, kick without logging, over-validate movement, or rely on client anti-cheat.
See references/full.md for detailed examples.
What ships with it: 1 file
7.8 KB alongside SKILL.md
references/
- full.md7.8 KB