trapspoofer
Allows scanning, spoofing (re-uploading and replacing) Roblox assets such as animations, sounds, images, and meshes, and managing Roblox accounts/groups for uploads.
Allows scanning a Roblox Studio session, pushing re-uploaded asset IDs back into Studio, and applying replacements across an entire place.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@trapspooferscan this place file and spoof all assets I don't own"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Disclaimer. TrapSpoofer is a tool for working with Roblox assets. Only use it with content you have the right to use. You are responsible for complying with the Roblox Terms of Use and third-party rights.
TrapSpoofer is a heavily reworked fork of ISpooferMotion V2, focused on three things: a simple, guided interface, a file mode that works without Studio open, and AI integration through MCP.
What it does
The app connects to Roblox Studio through a companion Luau plugin. Choose the target window in the Studio status menu, including when several windows have the same Place ID. Scans, progress and replacements stay attached to that window. The plugin works in the background; its panel opens only when you click its toolbar button.
Also included: ownership detection (skips assets you already own), pause / resume / retry of failed uploads, spoof history, auto-updates, English and Portuguese (BR) UI, and zero telemetry.
Related MCP server: Roblox Executor MCP
Install
Grab the latest version from the releases page.
Platform | Package |
Windows |
|
macOS (Apple Silicon) |
|
Linux |
|
The Roblox Studio plugin (TrapSpoofer.rbxmx) ships with every release. The app installs and keeps it in sync in your local Studio plugin folders automatically when it starts.
Windows Defender and other antivirus software may flag unsigned builds. TrapSpoofer has no commercial code-signing certificate. You can verify it by building from source.
Quick start
Accounts — the app can automatically import the accounts signed in to Roblox Studio on this computer. Each session is validated before it becomes a profile. Uploads can use this session, including for a selected group where the account has asset creation permission. An Open Cloud API key remains optional; when provided, the app uses that key for supported uploads.
Source — select a connected Studio window and scan it, open a
.rbxl/.rbxmfile, or paste IDs.Review — pick the assets to spoof (assets you already own are flagged).
Upload — hit Start spoof. Each asset is downloaded and re-uploaded.
Apply — the new IDs are pushed into Studio (or into a new file, in file mode). Save your place.
Studio accounts: Automatic connection is enabled in Settings → General. The app checks Studio's saved sessions on startup, imports valid accounts without duplicates, and signs in with the current Studio account when no valid profile is already selected. An existing profile and its upload group stay selected. Accounts → Import Studio accounts repeats detection after adding or reconnecting an account in Studio. Expired or rejected sessions are skipped, and cookies are saved in the system credential store rather than displayed in the interface. Manual cookie entry remains available.
Asset owners are cached on disk for seven days, up to 50,000 entries. Successful uploads immediately add the new asset's creator to the cache. Repeated runs reuse that information, while failed owner lookups remain eligible for retry. Clear it through the existing cache controls in Settings.
Optional API keys: Personal and group uploads can use the validated Roblox session. In Accounts or the Send step, Use Roblox session, even with saved keys keeps the profile's keys saved while excluding them from uploads. With this option off, a group upload uses the saved group key, then the personal key if there is no group key, then the session if neither key is available. Personal uploads never use the group key. The authentication notice shows the exact method selected and the required creator permissions. A rejected key can be replaced, cleared, or left saved while using session mode.
API keys do not guarantee shorter upload times. Both paths are subject to Roblox request limits and asset processing. Rate-limit notices report the actual authentication method and retry wait; the app does not invent a speed penalty for publishing without a key.
Native animation clips: Settings → Upload behavior lets you update the Animation ID normally, replace the Animation with its editable KeyframeSequence/CurveAnimation, or add that native clip as its parent while retaining the Animation. The Studio plugin downloads the original clip through AnimationClipProvider, preserves its keyframes/curves and playback metadata, and leaves the original instance intact if loading fails. The clip format is preserved, not converted. Normal ID replacement is the default. Game code that expects an Animation at the original path must be adapted when using either native clip mode. File mode continues to update IDs only.
Updates: Settings → General → Updates controls automatic checking and downloading. The app checks on startup and every six hours, with retries after failures. A downloaded update waits for you to choose Install and restart; installation is blocked while scans, uploads or replacements are active. Update the bundled plugin and reopen Studio when moving to a release with the new window-selection protocol.
AI integration (MCP)
TrapSpoofer runs a local MCP server so an AI assistant can drive the app: get_status, scan_studio, scan_file, list_assets, spoof_assets, get_job, push_to_studio, replace_ids, write_spoofed_file, and more. The AI / MCP tab in the app shows the URL, status and copy-ready config snippets.
Claude Code:
claude mcp add --transport http trapspoofer http://127.0.0.1:14380/mcpClaude Desktop / Cursor (stdio):
{ "mcpServers": { "trapspoofer": { "command": "C:/path/to/TrapSpoofer.exe", "args": ["--mcp"] } } }
The server only accepts local connections and can be turned off in Settings.
Development
Requirements
Requirement | Version |
Rust | Current stable |
Bun | 1.x or newer |
Node.js | 20 or newer |
Tauri | 2.x |
Roblox Studio | Current |
On Linux, Tauri also needs: libwebkit2gtk-4.1-dev, libssl-dev, libayatana-appindicator3-dev, librsvg2-dev.
Run
git clone https://github.com/TrapstarKS/TrapSpoofer.git
cd TrapSpoofer
bun install
bun run tauri:devCommand | Description |
| Start the desktop app in development mode |
| Run the full validation suite |
| Build the Studio plugin into |
| Format TypeScript, Rust and Luau |
| Run the frontend tests (Vitest) |
| Run the Rust tests |
| Bump the version everywhere before a release |
Releasing
bun run bump → commit → push to main. CI builds Windows, macOS and Linux in parallel and publishes the release (with latest.json for the auto-updater) whenever the version is new. Publication requires successful checks, successful builds and signed updater artifacts for every required platform. Run node --test scripts/updater-manifest.node.mjs to validate the manifest generator.
Project layout
TrapSpoofer/
├── src/ React/TypeScript UI (services/, stores/, mcp/, components/)
├── src-tauri/ Rust/Tauri backend, Studio bridge and MCP server
├── plugin/ Roblox Studio Luau plugin
├── scripts/ Build and release scripts
└── .github/ CI and templatesCredits & license
Based on ISpooferMotion V2 by IncredibroXP. TrapSpoofer is licensed under the GNU General Public License v3.0 or later — see LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Image and video AI tools and your own pipelines, run from any AI assistant.
OCR, transcription, file extraction, and image generation for AI agents via MCP.
Zero-setup MCP gateway securely connecting AI to your tools with authentication and workflows
Discover, inspect and run 63,000+ agent tools from one balance. Pay per call, no subscriptions.
Related MCP Servers
- FlicenseBqualityNot gradedmaintenanceEnables AI assistants to interact with running Roblox game instances by inspecting the game hierarchy, reading client-side scripts, and executing Lua code directly within the Roblox client through a WebSocket bridge.430 npm-
- AlicenseNot gradedqualityAmaintenanceEnables AI agents to interact with a running Roblox game client to execute Lua code, inspect scripts, spy on remotes, and more.139 npm216MIT
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to directly control Roblox, reverse engineer games, intercept network traffic, simulate user input, and manipulate game state through 150+ MCP tools.74 npmMIT
- AlicenseNot gradedqualityBmaintenanceEnables AI assistants to inspect and control a live Roblox client through an executor, including reading console output, exploring the instance tree, decompiling scripts, monitoring remote traffic, and running Luau code.MIT