Roblox Security

TabooHarmony/roblox-brain/skills/core/roblox-security

作者 TabooHarmony38826be57ee37bcf023e9c2b85681bea3909281c无许可证收录于 2026年10月9日更新于 2026年10月9日

Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.

仅含说明Security
AI 生成的概览

审计 Roblox 游戏代码中的漏洞利用途径、权威模型、远程调用、经济系统与 DataStore 流程。

功能
为 Roblox 项目提供安全检查清单,涵盖权威模型(经典复制与 Server Authority)、远程调用校验与限流、经济与购买验证、DataStore 会话锁定以及脚本沙箱。它还说明原生封禁 API 及其参数,并列出应避免的反模式。详细示例与配置字段表放在随附的参考文档中。
适用场景
在审查 Roblox 代码的权威、远程滥用、经济、存档、封禁或沙箱问题时使用。它面向审计,而非编写普通玩法代码。
运行要求
不含脚本,仅为说明性内容。它引用 Roblox 引擎 API 与文档,并需要访问随附的 references/full.md 文件。

Roblox Security

When to Load

Load for authority, remote abuse, economy, saves, bans, or sandboxing audits. Remote validation/rate limits: roblox-networking.

Quick Reference

Core: Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.

Authority Models

  • Classic replication: validate client requests against server state. Never trust client damage, currency, inventory, permissions, or positions.
  • Server Authority: Workspace.AuthorityMode = Server: the server owns core simulation while clients predict and recover from misprediction. Use BindToSimulation() (needs UseFixedSimulation), not blanket Heartbeat correction. Cheap for stock characters, rewrite-scale for authored simulation (full.md).
  • Both: validate attacks, purchases, teleports, permissions, and custom remotes at the server boundary.

Audit Checklist

CRITICAL: Server-authoritative state · Documented authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client code

HIGH: Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects · Validate ProximityPrompt/ClickDetector/DragDetector like remotes

MEDIUM: Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering · Script sandboxing for third-party code

Enforcement

Enforcement is a product decision with appeal implications, not an automatic response. The native ban API is server-only (Players:BanAsync / UnbanAsync / GetBanHistoryAsync; Players.BanningEnabled must be on). Duration -1 is permanent, 0 and other negatives are invalid; DisplayReason max 400 chars (filtered); PrivateReason max 1000, never client-shared; ApplyDeviceBlock lasts 24 hours and only UnbanAsync lifts it. Escalate via ban history; pcall every call (throttled HTTP). Config field table is in full.md.

Anti-Patterns

Don't obfuscate client code, use _G for security, kick without logging, over-validate movement, or rely on client anti-cheat.

See references/full.md for detailed examples.

来源与署名

来源:TabooHarmony/roblox-brain位于skills/core/roblox-security提交38826be

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架