roblox-security
Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.
Works with
--- name: roblox-security description: Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows. license: MIT --- # Roblox Security ## When to Load Load for exploit audits and hardening. Covers classic replication, opt-in Server Authority, remote abuse, economy attacks, and DataStore flows. Use `roblox-networking` for validation and rate-limit implementations. ## Quick Reference **Core:** Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model. ### Authority Models - **Classic replication:** validate client requests and custom movement against server state. Never trust client damage, currency, inventory, permissions, or positions. - **Server Authority:** with `Workspace.AuthorityMode = Server`, the server owns core simulation while clients predict and recover from misprediction. Use `BindToSimulation()` (requires `Workspace.UseFixedSimulation`), not blanket `Heartbeat` CFrame correction. Migration is cheap for stock characters but a rewrite-scale commitment for authored simulation (reality check in full.md). - **Both:** validate attacks, purchases, teleports, dashes, permissions, and custom remotes at the server boundary. ### Audit Checklist **CRITICAL:** Server-authoritative state · Choose and document the authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client or replicated code **HIGH:** Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects **MEDIUM:** Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering ### Anti-Patterns Don't obfuscate client code, use `_G` for security, kick without logging, over-validate movement, or rely on client anti-cheat. See `references/full.md` for detailed examples.
More General & Other skills
find-skills
vercel-labs/skills
Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
grill-me
mattpocock/skills
A relentless interview to sharpen a plan or design.
grill-with-docs
mattpocock/skills
A relentless interview to sharpen a plan or design, which also creates docs (ADR's and glossary) as we go.

