Install
$ agentstack add skill-tabooharmony-roblox-brain-roblox-security ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
When to Load
Load this skill when designing security systems, auditing code for vulnerabilities, or hardening a Roblox game against exploit vectors. Covers movement hacks, remote abuse, economy attacks, DataStore exploits, and server-authority patterns.
Quick Reference
Core: Client is always compromised. Server = only source of truth.
Vectors & Mitigations
| Vector | Attack | Fix | |--------|--------|-----| | Movement | Speed/teleport/fly/noclip | Server velocity+pos checks per Heartbeat | | Remote | Spam, arg spoof, replay | Rate limiter + validate arg types + idempotency | | Economy | Dupe, negative qty | Session lock, atomic ops, qty > 0 | | DataStore | Save spam, session hijack | Server-controlled saves, JobId session lock | | General | Client trusts values | Server computes ALL game state |
Key Patterns
-- Rate limiter
local function checkRate(player, remote): boolean
local now = os.clock(); local lim = rateLimits[player]
if not lim then lim = {}; rateLimits[player] = lim end
if now - (lim[remote] or 0) < 0.1 then return false end
lim[remote] = now; return true
end
-- Server-authoritative damage (never trust client)
AttackRemote.OnServerEvent:Connect(function(player, targetId)
local weapon = getEquippedWeapon(player)
local target = resolveTarget(targetId)
if not weapon or not target or not isInRange(player, target) then return end
target.Humanoid:TakeDamage(weapon.BaseDamage * getMultiplier(player))
end)
Audit Checklist
CRITICAL: Server-authoritative state · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No sensitive LocalScript logic
HIGH: Server-validated movement · BindToClose protection · Atomic trading · Never trust client values
MEDIUM: Server cooldowns · Server leaderboards · Anti-AFK rewards · TextService filtering
Anti-Patterns
Don't: obfuscate client, use _G for security, kick without logging, over-validate movement, rely on client anti-cheat
See references/full.md for detailed examples.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: TabooHarmony
- Source: TabooHarmony/roblox-brain
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.