Install
$ agentstack add skill-codephobiia-claude-roblox-game-studio-code-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
/code-review — Luau Code Review
Delegate to: lead-programmer (with exploit-security-specialist for security concerns)
Scope
Ask the user:
- "Which files should I review? (provide paths, a directory, or say 'recent changes')"
- For git-based review:
git diff HEAD~1orgit diff main...HEADstyle
Review Checklist
Structure & Style
- [ ] Module pattern:
local Module = {} ... return Module - [ ] Service caching at top:
local Players = game:GetService("Players") - [ ] Type annotations on public functions
- [ ] Naming conventions (PascalCase modules, camelCase functions, UPPER_SNAKE constants)
- [ ] No magic numbers (all constants externalized)
- [ ] No
print()left in production code (unless behind a debug flag)
Safety & Correctness
- [ ] No deprecated APIs:
wait(),spawn(),delay()— should usetask.wait(),task.spawn(),task.defer() - [ ] All DataStore/HttpService/MarketplaceService calls in
pcall - [ ] Retry logic for transient failures
- [ ] No infinite loops without yield
- [ ] Proper cleanup (Trove/Maid/manual disconnection)
Server Authority (Security)
- [ ] No client-side game state mutations
- [ ] All RemoteEvent handlers validate argument types
- [ ] All RemoteEvent handlers validate argument ranges
- [ ] Rate limiting on player-triggered remotes
- [ ] No RemoteFunction invoked client → server (server hang risk)
- [ ] Purchase processing via
MarketplaceService.ProcessReceiptserver-side
Performance
- [ ] No expensive work per Heartbeat without throttling
- [ ] Cached references (not repeated
workspace.Xlookups) - [ ] No string concatenation in loops (use
table.concat) - [ ] Table allocations minimized in hot paths
- [ ] Connections disconnected on cleanup
Architecture
- [ ] No circular module dependencies
- [ ] Clear separation: shared / server / client
- [ ] Shared modules don't leak server secrets
- [ ] Config values externalized to dedicated config module
Output Format
# Code Review: [Scope]
## Summary
- Files reviewed: X
- Critical issues: X
- Important issues: X
- Suggestions: X
## Critical (must fix before merge)
1. **[filepath:line]**: [issue]
- Reason: [why it's critical]
- Fix: [specific code change]
## Important
...
## Suggestions
...
## Kudos
- [Things done well — reinforce good patterns]
Present the review to the user. Never apply fixes without approval. Offer to delegate fixes to the appropriate specialist.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: CodePhobiia
- Source: CodePhobiia/claude-roblox-game-studio
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.