Roblox Security

TabooHarmony/roblox-brain/skills/core/roblox-security

by TabooHarmony38826be57ee37bcf023e9c2b85681bea3909281cNo licenseListed Oct 9, 2026Updated Oct 9, 2026

Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.

Instructions onlySecurity
AI-generated overview

Audits Roblox game code for exploit vectors, authority models, remotes, economy, and DataStore flows.

What it does
Provides a security audit checklist for Roblox projects, covering authority models (classic replication and Server Authority), remote validation and rate limiting, economy and purchase verification, DataStore session locking, and script sandboxing. It also documents the native ban API and its parameters, and lists anti-patterns to avoid. Detailed examples and a configuration field table are deferred to a bundled reference document.
When to use it
Use it when reviewing Roblox code for authority, remote abuse, economy, save, ban, or sandboxing issues. It is aimed at audits rather than writing ordinary gameplay code.
Requirements
No scripts; instructions only. It references Roblox engine APIs and documentation, and expects access to the bundled references/full.md file.

Roblox Security

When to Load

Load for authority, remote abuse, economy, saves, bans, or sandboxing audits. Remote validation/rate limits: roblox-networking.

Quick Reference

Core: Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.

Authority Models

  • Classic replication: validate client requests against server state. Never trust client damage, currency, inventory, permissions, or positions.
  • Server Authority: Workspace.AuthorityMode = Server: the server owns core simulation while clients predict and recover from misprediction. Use BindToSimulation() (needs UseFixedSimulation), not blanket Heartbeat correction. Cheap for stock characters, rewrite-scale for authored simulation (full.md).
  • Both: validate attacks, purchases, teleports, permissions, and custom remotes at the server boundary.

Audit Checklist

CRITICAL: Server-authoritative state · Documented authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client code

HIGH: Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects · Validate ProximityPrompt/ClickDetector/DragDetector like remotes

MEDIUM: Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering · Script sandboxing for third-party code

Enforcement

Enforcement is a product decision with appeal implications, not an automatic response. The native ban API is server-only (Players:BanAsync / UnbanAsync / GetBanHistoryAsync; Players.BanningEnabled must be on). Duration -1 is permanent, 0 and other negatives are invalid; DisplayReason max 400 chars (filtered); PrivateReason max 1000, never client-shared; ApplyDeviceBlock lasts 24 hours and only UnbanAsync lifts it. Escalate via ban history; pcall every call (throttled HTTP). Config field table is in full.md.

Anti-Patterns

Don't obfuscate client code, use _G for security, kick without logging, over-validate movement, or rely on client anti-cheat.

See references/full.md for detailed examples.

Source and attribution

Source:TabooHarmony/roblox-braininskills/core/roblox-securityat commit38826be

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal