Roblox security
Give your AI coding agent a Roblox brain. Curated skills for Roblox Studio development.
npx -y skills add TabooHarmony/roblox-brain --skill roblox-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 18 stars18 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.
SKILL.md
2.9 KB, as published. Nobody here has run it
Roblox Security
When to Load
Load for exploit audits and hardening. Covers classic replication, opt-in Server Authority, remote abuse, economy attacks, and DataStore flows. Use roblox-networking for validation and rate-limit implementations.
Quick Reference
Core: Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.
Authority Models
- Classic replication: validate client requests and custom movement against server state. Never trust client damage, currency, inventory, permissions, or positions.
- Server Authority: with
Workspace.AuthorityMode = Serverand its required settings, the server owns core simulation while clients predict and recover from misprediction. UseBindToSimulation()(requiresWorkspace.UseFixedSimulationenabled in Studio), not blanketHeartbeatCFrame correction. - Both: validate attacks, purchases, teleports, dashes, permissions, and custom remotes at the server boundary.
Vectors & Mitigations
| Vector | Attack | Fix |
|---|---|---|
| Movement | Custom dash, teleport, or locomotion abuse | Server state and transition checks; under Server Authority, keep simulation logic in BindToSimulation() (requires Workspace.UseFixedSimulation enabled in Studio) and do not add blanket CFrame snap-back |
| Remote | Spam, arg spoof, replay | Rate limiter + validate arg types + idempotency |
| Economy | Dupe, negative qty | Session lock, atomic ops, qty > 0 |
| DataStore | Save spam, session hijack | Server-controlled saves, maintained session ownership protocol |
| General | Client trusts values | Server computes ALL game state |
Audit Checklist
CRITICAL: Server-authoritative state · Choose and document the authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client or replicated code
HIGH: Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects
MEDIUM: Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering
Anti-Patterns
Don't obfuscate client code, use _G for security, kick without logging, over-validate movement, or rely on client anti-cheat.
See references/full.md for detailed examples.