Roblox Security
SkillSecurityUse when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Roblox Security skill
What this skill tells your AI
The instructions your AI receives, as published by tabooharmony/roblox-brain in skills/roblox-security/SKILL.md and read by ahel’s review.
When to Load
Load for exploit audits and hardening. Covers classic replication, opt-in Server Authority, remote abuse, economy attacks, and DataStore flows. Use roblox-networking for validation and rate-limit implementations.
Quick Reference
Core: Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.
Authority Models
- Classic replication: validate client requests and custom movement against server state. Never trust client damage, currency, inventory, permissions, or positions.
- Server Authority: with
Workspace.AuthorityMode = Server, the server owns core simulation while clients predict and recover from misprediction. UseBindToSimulation()(requiresWorkspace.UseFixedSimulation), not blanketHeartbeatCFrame correction. Migration is cheap for stock characters but a rewrite-scale commitment for authored simulation (reality check in full.md). - Both: validate attacks, purchases, teleports, dashes, permissions, and custom remotes at the server boundary.
Audit Checklist
CRITICAL: Server-authoritative state · Choose and document the authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client or replicated code
HIGH: Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects
MEDIUM: Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering
Anti-Patterns
Don't obfuscate client code, use _G for security, kick without logging, over-validate movement, or rely on client anti-cheat.
See references/full.md for detailed examples.
Signals
- GitHub stars
- 44
- Forks
- 3
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
roblox-security- Source
- github.com/tabooharmony/roblox-brain