roblox-security
Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.
How do I install this agent skill?
npx skills add https://github.com/tabooharmony/roblox-brain --skill roblox-securityIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides comprehensive security guidelines and best practices for auditing Roblox games. It covers authority models, remote validation, economy security, and native enforcement APIs. No security issues, malicious patterns, or suspicious external dependencies were detected.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Roblox Security
When to Load
Load for authority, remote abuse, economy, saves, bans, or sandboxing audits. Remote validation/rate limits: roblox-networking.
Quick Reference
Core: Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.
Authority Models
- Classic replication: validate client requests against server state. Never trust client damage, currency, inventory, permissions, or positions.
- Server Authority:
Workspace.AuthorityMode = Server: the server owns core simulation while clients predict and recover from misprediction. UseBindToSimulation()(needsUseFixedSimulation), not blanketHeartbeatcorrection. Cheap for stock characters, rewrite-scale for authored simulation (full.md). - Both: validate attacks, purchases, teleports, permissions, and custom remotes at the server boundary.
Audit Checklist
CRITICAL: Server-authoritative state · Documented authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client code
HIGH: Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects · Validate ProximityPrompt/ClickDetector/DragDetector like remotes
MEDIUM: Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering · Script sandboxing for third-party code
Enforcement
Enforcement is a product decision with appeal implications, not an automatic response. The native ban API is server-only (Players:BanAsync / UnbanAsync / GetBanHistoryAsync; Players.BanningEnabled must be on). Duration -1 is permanent, 0 and other negatives are invalid; DisplayReason max 400 chars (filtered); PrivateReason max 1000, never client-shared; ApplyDeviceBlock lasts 24 hours and only UnbanAsync lifts it. Escalate via ban history; pcall every call (throttled HTTP). Config field table is in full.md.
Anti-Patterns
Don't obfuscate client code, use _G for security, kick without logging, over-validate movement, or rely on client anti-cheat.
See references/full.md for detailed examples.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/tabooharmony/roblox-brain/roblox-security">View roblox-security on skillZs</a>