# Roblox Security

> Use when auditing Roblox code for exploit vectors, authority models, remotes, economy, and DataStore flows.

- Skill: `tabooharmony/roblox-security` (Agent Skill, multi-file: 2 files)
- Install (CLI): `npx skillmds@latest add tabooharmony/roblox-security`
- Raw SKILL.md: https://api.skillmd.com/api/skills/tabooharmony/roblox-security/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: tabooharmony (https://skillmd.com/u/tabooharmony)
- Updated: 2026-09-10
- Page: https://skillmd.com/skills/tabooharmony/roblox-security

---


# Roblox Security

## When to Load

Load for exploit audits and hardening. Covers classic replication, opt-in Server Authority, remote abuse, economy attacks, and DataStore flows. Use `roblox-networking` for validation and rate-limit implementations.

## Quick Reference

**Core:** Client is always compromised. The server remains the source of truth, but the implementation depends on the authority model.

### Authority Models

- **Classic replication:** validate client requests and custom movement against server state. Never trust client damage, currency, inventory, permissions, or positions.
- **Server Authority:** with `Workspace.AuthorityMode = Server`, the server owns core simulation while clients predict and recover from misprediction. Use `BindToSimulation()` (requires `Workspace.UseFixedSimulation`), not blanket `Heartbeat` CFrame correction. Migration is cheap for stock characters but a rewrite-scale commitment for authored simulation (reality check in full.md).
- **Both:** validate attacks, purchases, teleports, dashes, permissions, and custom remotes at the server boundary.

### Audit Checklist

**CRITICAL:** Server-authoritative state · Choose and document the authority model · Validate all arg types · Rate limit remotes · Session-lock DataStore · No client currency mutations · ProcessReceipt verification · No secrets in client or replicated code

**HIGH:** Validate custom movement and action transitions · BindToClose protection · Atomic trading · Never trust client values · Use InputActions for simulation input in Server Authority projects

**MEDIUM:** Server cooldowns · server-computed leaderboards · anti-AFK reward checks · TextService filtering

### Anti-Patterns

Don't obfuscate client code, use `_G` for security, kick without logging, over-validate movement, or rely on client anti-cheat.

See `references/full.md` for detailed examples.

