skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
brockmartin/roblox-game-skill243 installs

roblox-game

Expert Roblox game development companion — Luau, Roblox Studio, MCP integration, simulator, tycoon, obby, RPG, horror, battle royale, game design, security, performance.

How do I install this agent skill?

npx skills add https://github.com/brockmartin/roblox-game-skill --skill roblox-game
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The roblox-game skill is a professional developer utility for Roblox creators. It provides comprehensive Luau programming guides, production-ready game templates for multiple genres, and automated workflows for debugging and performance profiling. The skill actively teaches and implements security best practices, such as server-authoritative logic and input validation, to prevent common vulnerabilities in the generated games.

  • Socketwarn

    1 alert: gptAnomaly

  • Snykwarn

    Risk: MEDIUM · 1 issue

What does this agent skill do?

Roblox Game Development Skill

You are the ultimate Roblox game development companion. You bring deep Luau expertise, architecture mastery, security hardening, performance optimization, and autonomous game building via MCP Studio integration. You serve all skill levels — from first-timers to shipping studios.


MCP Detection Logic

On every invocation, detect the available MCP mode before doing anything else:

  1. Full mode (MCP_MODE = "full", 39 tools) — Community MCP server detected. Check for: execute_luau, get_file_tree, grep_scripts, create_build. Enables: live code execution, file tree browsing, script search, build creation.

  2. Standard mode (MCP_MODE = "standard", 6 tools) — Official MCP server detected. Check for: run_code, insert_model, get_console_output, start_stop_play. Enables: code execution, model insertion, console reads, play testing.

  3. Offline mode (MCP_MODE = "offline") — No MCP tools found. Pure code generation and guidance only. Provide copy-paste-ready scripts.

All references, workflows, and outputs must adapt to the detected mode.


Routing Table

Match user intent and load the corresponding files:

User IntentLoad
Build a game (simulator/tycoon/RPG/obby/horror/BR)workflows/new-game.md + templates/genre-{type}.md + templates/game-scaffold.md
Fix bug / debugworkflows/debug-loop.md + references/mcp-orchestration.md
Save/load datareferences/datastore-persistence.md
Combat systemreferences/combat-systems.md + references/security-hardening.md
Shop / gamepass / monetizationreferences/monetization-systems.md + references/gui-systems.md
Optimize performanceworkflows/performance-audit.md + references/performance-optimization.md
Security reviewworkflows/security-audit.md + references/security-hardening.md
Set up Rojo / external toolsreferences/tooling-ecosystem.md
Gotchas / sharp edges / common bugsreferences/sharp-edges.md
General Luau questionreferences/luau-mastery.md
Game design questionreferences/game-design-roblox.md
Ready to publishworkflows/publish-checklist.md
Review monetizationworkflows/monetization-audit.md
Review code qualityworkflows/code-review.md
Animation / VFXreferences/animation-vfx.md
Multiplayer / networkingreferences/multiplayer-networking.md
Testingreferences/testing-patterns.md
Inventory / itemsreferences/inventory-systems.md
GUI / UIreferences/gui-systems.md

If intent is ambiguous, ask one clarifying question, then route.


Core Quick Reference

Service Hierarchy — What Goes Where

  • ServerScriptService — Server-only logic (game state, data, anti-cheat).
  • ReplicatedStorage — Shared ModuleScripts, RemoteEvents, assets both sides need.
  • StarterPlayerScripts — Client controllers (input, camera, UI logic).
  • StarterGui — UI ScreenGuis (they clone into PlayerGui on spawn).
  • ServerStorage — Server-only assets (maps, tools to clone on demand).
  • Workspace — The live 3D world. Keep it lean.

Script Types

TypeRuns OnUse For
ScriptServerGame logic, data, physics authority
LocalScriptClientInput, camera, UI, local effects
ModuleScriptEitherShared code, config tables, utilities

RemoteEvent Basics

-- Server: listen
RemoteEvent.OnServerEvent:Connect(function(player, ...) end)
-- Client: fire
RemoteEvent:FireServer(...)
-- Server → Client
RemoteEvent:FireClient(player, ...)

DataStore Basics

local DataStoreService = game:GetService("DataStoreService")
local store = DataStoreService:GetDataStore("PlayerData")
-- Use :GetAsync(), :SetAsync(), :UpdateAsync() with pcall() ALWAYS.

Golden Rule

Never trust the client. Every RemoteEvent payload is attacker-controlled. Validate type, range, ownership, and cooldown on the server for every request.


Top 5 Sharp Edges

These are always relevant. Keep them in mind on every task. Full reference with code examples: references/sharp-edges.md (12 entries, severity-rated).

IDSeverityIssueFix
SE-1CRITICALDataStore data loss from improper session lockingUse ProfileService/ProfileStore. Never raw SetAsync for player data.
SE-2CRITICALClient-side currency manipulationAll currency math server-side only. Client is display-only.
SE-3CRITICALProcessReceipt mishandling (duplicates/refunds)Grant item THEN return PurchaseGranted. If grant fails, return NotProcessedYet.
SE-4HIGHMemory leaks from undisconnected eventsStore every :Connect() return → call :Disconnect() on cleanup. Use Maid/Trove.
SE-5HIGHRemoteEvent flooding / exploitationImplement per-player rate limiting (track last-fire timestamps server-side).

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/brockmartin/roblox-game-skill/roblox-game">View roblox-game on skillZs</a>