Install
$ agentstack add skill-tabooharmony-roblox-brain-roblox-cloud ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
roblox-cloud
When to Load
Load this skill when the task involves Roblox Open Cloud REST APIs, API-key authentication, webhook setup, or HttpService calls to Open Cloud endpoints. Skip it for OAuth flows (use roblox-oauth), persistent data design (use roblox-data), gameplay networking (use roblox-networking), or pure engine API lookups (use roblox-api).
Quick Reference
Open Cloud REST APIs
- Base:
https://apis.roblox.com/cloud/v2/…(v1 for legacy) - Auth:
x-api-key:header for server-to-server - Content-Type:
application/jsonfor bodies - Pagination: read
nextPageToken, pass it back aspageTokenquery param - Update masks: use
updateMaskquery param for partial PATCH - Long-running ops: poll the returned Operation resource with exponential backoff
- Error codes:
INVALID_ARGUMENT(bad input),PERMISSION_DENIED/INSUFFICIENT_SCOPE(auth),RESOURCE_EXHAUSTED/429 (rate limit → backoff),UNAVAILABLE(transient → retry)
API Keys
- Use for: CI jobs, bots, web backends, in-experience automation (non-user)
- Each key has scoped permissions—confirm required scopes before coding
- Creator permissions AND key scopes must both allow the action
- Never store keys as plain text in experiences—use Secrets
Webhooks
- Requires public HTTPS POST endpoint
- Return 2XX within 5 seconds; process event async
- Verify
roblox-signatureheader when secret is configured - Deduplicate by
NotificationId—deliveries may repeat - Reject stale timestamps
HttpService Constraints (in-experience)
- Only certain Open Cloud endpoints are supported
- Allowed headers:
x-api-key,Content-TypeONLY - API key must come from a Secret (not plain string)
- HTTPS only; path params cannot contain
.. - Check endpoint support before coding
Handoffs
- OAuth / user consent →
roblox-oauth - Data schema / DataStore design →
roblox-data - Remotes / networking →
roblox-networking - Engine API lookup only →
roblox-api
References
references/full.md— complete instructions, decision rules, checklist, common mistakes, examplesreferences/— per-topic docs: open-cloud-overview, api-patterns-errors-types-scopes-and-rate-limits, webhooks-documentation, http-service, openapi-documentation, cloud-reference-json-files
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: TabooHarmony
- Source: TabooHarmony/roblox-brain
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.