Install
$ agentstack add skill-tabooharmony-roblox-brain-roblox-code-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
/code-review - Code Quality Review
Review Roblox projects with security, performance, and monetization lenses. Apply relevant lenses based on what changed — not all every time. Full details: references/full.md.
When to Load
- User runs
/code-reviewor asks for code review on Roblox/Luau code - User asks to audit security, performance, networking, monetization, or data persistence
- User asks about Roblox best practices for remotes, data saving, or code organization
Quick Reference
8-Step Review
- Project Scan — scripts, folders, naming, Rojo/Wally/Studio
- Organization — correct services, PascalCase modules, no orphans
- Code Quality —
wait()→task.wait(),spawn()→task.spawn(),delay()→task.delay(), globals - Architecture — single responsibility, no circular requires, server/client split
- Security — validate remotes server-side, no client-trusted state, rate-limit
- Performance — consolidate Heartbeat, cache services, disconnect events
- Report — Grade A-F. Severity: Critical/High/Medium/Low
- Refactor — Immediate → Short-term → Long-term
Remote Types
- RemoteEvent — fire-and-forget | RemoteFunction — blocking, sparse, never per-frame
- UnreliableRemoteEvent — loss-tolerant VFX/position ONLY, never currency/inventory/damage
Security
- Validate remotes:
typeof(), range, cooldown, authorization - State changes server-authoritative. No sensitive data in ReplicatedStorage
- Rate-limit all remotes per-player
Performance
wait()/spawn()/delay()→task.*. One Heartbeat per script- Parts: Unions
- Disconnect every
:Connect(). Batch remotes. Cache GetService()
Networking
- Remotes under
ReplicatedStorage.Remotes.{Category}, PascalCase VerbNoun - Separate reliable (state) from unreliable (cosmetics). FireClient > FireAllClients
Data Persistence
- Always ProfileStore, never raw DataStoreService
- Template: DataVersion, defaults, JSON-only types. Reconcile() after load
- Session lock: AddUserId, ListenToRelease, ForceLoad
- Lifecycle: PlayerAdded→load, PlayerRemoving→sync+release, BindToClose→parallel
Monetization
- Map GamePasses/DevProducts. ProcessReceipt: grant then confirm
- Pricing: Entry 25-49R, Mid 99-199R, Premium 499-999R
- Flag: loot odds, FOMO, pay-to-win, dark patterns
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: TabooHarmony
- Source: TabooHarmony/roblox-brain
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.