Roblox Security

TabooHarmony/roblox-brain/skills/core/roblox-security

作者 TabooHarmony38826be57ee37bcf023e9c2b85681bea3909281c無授權條款收錄於 2026年10月9日更新於 2026年10月9日

Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.

僅含說明Security
AI 產生的概覽

稽核 Roblox 遊戲程式碼中的漏洞利用途徑、權威模型、遠端呼叫、經濟系統與 DataStore 流程。

功能
為 Roblox 專案提供安全檢查清單,涵蓋權威模型(經典複寫與 Server Authority)、遠端呼叫驗證與限流、經濟與購買驗證、DataStore 工作階段鎖定,以及指令碼沙箱。它也說明原生封鎖 API 及其參數,並列出應避免的反模式。詳細範例與設定欄位表放在隨附的參考文件中。
適用情境
在審查 Roblox 程式碼的權威、遠端濫用、經濟、存檔、封鎖或沙箱問題時使用。它著重稽核,而非撰寫一般玩法程式碼。
執行需求
不含指令碼,僅為說明性內容。它引用 Roblox 引擎 API 與文件,並需要存取隨附的 references/full.md 檔案。

Roblox Security

When to Load

Load for authority, remote abuse, economy, saves, bans, or sandboxing audits. Remote validation/rate limits: roblox-networking.

Quick Reference

Core: Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.

Authority Models

  • Classic replication: validate client requests against server state. Never trust client damage, currency, inventory, permissions, or positions.
  • Server Authority: Workspace.AuthorityMode = Server: the server owns core simulation while clients predict and recover from misprediction. Use BindToSimulation() (needs UseFixedSimulation), not blanket Heartbeat correction. Cheap for stock characters, rewrite-scale for authored simulation (full.md).
  • Both: validate attacks, purchases, teleports, permissions, and custom remotes at the server boundary.

Audit Checklist

CRITICAL: Server-authoritative state · Documented authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client code

HIGH: Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects · Validate ProximityPrompt/ClickDetector/DragDetector like remotes

MEDIUM: Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering · Script sandboxing for third-party code

Enforcement

Enforcement is a product decision with appeal implications, not an automatic response. The native ban API is server-only (Players:BanAsync / UnbanAsync / GetBanHistoryAsync; Players.BanningEnabled must be on). Duration -1 is permanent, 0 and other negatives are invalid; DisplayReason max 400 chars (filtered); PrivateReason max 1000, never client-shared; ApplyDeviceBlock lasts 24 hours and only UnbanAsync lifts it. Escalate via ban history; pcall every call (throttled HTTP). Config field table is in full.md.

Anti-Patterns

Don't obfuscate client code, use _G for security, kick without logging, over-validate movement, or rely on client anti-cheat.

See references/full.md for detailed examples.

來源與署名

來源:TabooHarmony/roblox-brain位於skills/core/roblox-security提交38826be

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架