Skip to main content
Glama
okenjioxx

Roblox Executor MCP Server

by okenjioxx

Generate a random symmetric key with crypt.generatekey

crypt-generate-key
Read-onlyIdempotent

Generate a cryptographically random symmetric key as a Base64 string for use with crypt-encrypt and crypt-decrypt operations.

Instructions

Generate a cryptographically random symmetric key using the executor's crypt.generatekey(). The key is returned as a Base64 string suitable for use with crypt-encrypt / crypt-decrypt. This is a pure, side-effect-free compute that runs entirely in-game. Requires crypt.generatekey; on an executor without it, it returns { error } instead of throwing. The call is pcall-guarded. Returns { key } or { error }. Signature: { threadContext: number?, timeoutMs: number? }. Phase: observe; cost=medium; idempotency=read-only. Requires: active-client. Produces: structured-result. Safety: read-only. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
timeoutMsNoOptional per-call deadline in milliseconds; omit it to use the tool or server default.
threadContextNoOptional Roblox thread identity for this call; omit it to use the server default.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0-spies.2

TDQS

A4.3/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations: discloses it is a pure, side-effect-free in-game compute, names the required `crypt.generatekey` capability, and states the failure contract (returns { error } instead of throwing, pcall-guarded). This is exactly the behavioral context annotations can't convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose and return shape, which is good, but the trailing metadata (`idempotency=read-only`, `Safety: read-only`) duplicates the readOnlyHint/idempotentHint annotations and adds boilerplate weight without new information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the return contract itself ("Returns { key } or { error }") and names the fallback tool (tool-schema) for deeper details. Nothing an agent needs to invoke it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so both params are already documented with their own descriptions. The description restates the signature and default-omission behavior but adds no new syntax or constraint meaning, so the baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ("Generate a cryptographically random symmetric key") and names the downstream siblings it feeds (crypt-encrypt / crypt-decrypt). An agent can distinguish it from crypt-generate-bytes or crypt-hash without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context for use: the key is Base64-suitable for crypt-encrypt / crypt-decrypt, and it notes the active-client prerequisite. It does not explicitly contrast against the nearest alternative (crypt-generate-bytes), so it stops short of full when/when-not routing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools