tabooharmony/roblox-brain

roblox-security

Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.

Trending #9617 First seen May 28, 2026

Installation

$ npx skills add tabooharmony/roblox-brain --skill roblox-security

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from tabooharmony/roblox-brain · top by installs.

npx skills add tabooharmony/roblox-brain

Browse all from tabooharmony/roblox-brain

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Also listed on

Alternate registries and mirrors of this skill.

Repository health

Stars 42
License LICENSE
Default branch main
Open issues 0
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,629 B
  • docs SUMMARY.md 130 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 533 installs

SKILL.md

Roblox Security

When to Load

Load for exploit audits and hardening. Covers classic replication, opt-in Server Authority, remote abuse, economy attacks, and DataStore flows. Use roblox-networking for validation and rate-limit implementations.

Quick Reference

Core: Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.

Authority Models

  • Classic replication: validate client requests and custom movement against server state. Never trust client damage, currency, inventory, permissions, or positions.
  • Server Authority: with Workspace.AuthorityMode = Server, the server owns core simulation while clients predict and recover from misprediction. Use BindToSimulation() (requires Workspace.UseFixedSimulation), not blanket Heartbeat CFrame correction. Migration is cheap for stock characters but a rewrite-scale commitment for authored simulation (reality check in full.md).
  • Both: validate attacks, purchases, teleports, dashes, permissions, and custom remotes at the server boundary.

Audit Checklist

CRITICAL: Server-authoritative state · Choose and document the authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client or replicated code

HIGH: Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects

MEDIUM: Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering

Anti-Patterns

Don't obfuscate client code, use _G for security, kick without logging, over-validate movement, or rely on client anti-cheat.

See references/full.md for detailed examples.