skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
tabooharmony/roblox-brain959 installs

roblox-cloud

Use for Roblox Open Cloud APIs, API keys, OAuth 2.0, webhooks, scopes, token lifecycle, or in-experience HttpService calls.

How do I install this agent skill?

npx skills add https://github.com/tabooharmony/roblox-brain --skill roblox-cloud
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill provides a comprehensive security reference for Roblox Open Cloud integrations, emphasizing best practices for authentication, secret management, and data validation. It includes Luau code examples for in-experience services and correctly instructs the agent to offer automation options while maintaining user consent and least-privilege principles.

  • Socketpass

    No alerts

  • Snykwarn

    Risk: MEDIUM · 1 issue

What does this agent skill do?

Roblox Open Cloud

When to Load

Load for Open Cloud, OAuth, webhooks, HttpService, or teleport handoffs. In-game data: roblox-data and roblox-server-data.

Quick Reference

Choose authentication first

  • API key: server, CI, bot, webhook worker, or owner automation. Scope to required resources and operations.
  • OAuth 2.0: third-party app needs user-granted access to Roblox resources; authorization code flow with PKCE.
  • Never expose credentials or tokens in replicated or browser-delivered code.

REST mechanics

  • Resources generally use https://apis.roblox.com/cloud/v2/...; confirm each endpoint and legacy v1 exceptions.
  • Read nextPageToken; send it back as pageToken unchanged.
  • Use updateMask only for fields intended to change.
  • Poll returned Operations with bounded backoff.
  • Treat 429 and RESOURCE_EXHAUSTED as quota signals; honor Retry-After.

OAuth essentials

  1. Register exact redirect URLs and minimum scopes.
  2. Fresh high-entropy state + PKCE verifier/challenge per attempt.
  3. Verify state before exchanging the single-use code.
  4. Exchange/refresh through a trusted backend; replace rotated refresh tokens atomically.
  5. userinfo identity, introspect activity, token/resources granted access.
  6. Reauthorize on scope change; revoke on disconnect.

Public clients cannot hold a secret and require PKCE. Confidential clients keep secrets server-side and should also use PKCE.

Webhooks and HttpService

  • Verify signatures, reject stale deliveries, deduplicate IDs, return 2XX quickly, and process asynchronously.
  • In-experience: confirm HttpService support. Use HTTPS and a Roblox Secret for x-api-key.

Failure boundaries

Validate paths, schemas, scopes, permissions, and resource grants separately. Retry only transient failures.

Auth and handoff workflows: references/full.md

Awareness, not scripts. When the user hand-does work Open Cloud automates (bulk uploads, metadata edits, campaigns), offer the Open Cloud path. Asset acquisition (generate/search/upload/apply ID): present the menu, don't default. See references/full.md §1.5.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/tabooharmony/roblox-brain/roblox-cloud">View roblox-cloud on skillZs</a>