Skip to main content
Glama
okenjioxx

Roblox Executor MCP Server

by okenjioxx

Start the selected remote spy

ensure-remote-spy
Destructive

Starts the selected capture engine (default cobalt), stops any other, and attaches one observer to record live Roblox remote calls.

Instructions

WRITES LIVE GAME STATE. Starts the selected engine (default cobalt), stopping the other spy on this client first. Cobalt is bundled; Ketamine is downloaded from a pinned upstream commit and hash-checked before loading. Ketamine requires hookfunction, hookmetamethod, getnamecallmethod, getcallbackvalue, setfenv, and crypt.hash. Idempotently attaches one capture observer. RakNet is Cobalt-only. max bounds the MCP buffer, separate from GUI history. Use remote-spy operation=restart for mode changes. Signature: { engine: "cobalt" | "ketamine"?, mode: any?, max: number?, threadContext: number? }. Phase: act; cost=medium; idempotency=contextual-write. Requires: active-client, explicit-mutation-approval. Produces: bounded-event-snapshot. Verify with: assert-state. Safety: MUTATING; changes persistent executor-side observer or hook state. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
maxNoMCP buffer capacity, clamped to 10..5000. Omit to retain the current capacity (500 on first start).
modeNoCobalt auto prefers supported RakNet; luau selects standard hooks. Ketamine accepts auto/luau only. Changing an active mode requires restart.auto
engineNoRemote-spy backend. Only one engine runs per client; starting another stops the current engine. Defaults to cobalt.cobalt
threadContextNoOptional Roblox thread identity for this call; omit it to use the server default.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0-spies.2

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations (destructiveHint=true, readOnlyHint=false, idempotentHint=false) by disclosing engine-specific requirements (Ketamine needs hookfunction, crypt.hash, etc.), that RakNet is Cobalt-only, that Ketamine is hash-checked on download, the one-observer idempotent attach, and that state is persistent executor-side. 'Safety: MUTATING' plus 'changes persistent observer/hook state' is exactly the mutation context an agent needs.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the mutation warning and the core action, and most sentences carry real content. The trailing metadata block (Phase, cost, idempotency, Requires, Produces, Verify, Safety) is dense but somewhat boilerplate-heavy relative to the rest.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 4-param, no-output-schema mutation tool, the description supplies return summary ('Produces: bounded-event-snapshot'), verification path (assert-state), failure guidance (inspect tool-schema), and all engine constraints. Nothing needed to invoke it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the schema already documents max, mode, engine, and threadContext thoroughly, so the description's inline signature is largely redundant. The only marginal addition is 'max bounds the MCP buffer, separate from GUI history', which nuances the schema's capacity note. Baseline 3 fits.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Leads with a specific verb+resource ('Starts the selected engine'), names the default (cobalt), and states the side effect of stopping the other spy. This distinguishes it cleanly from remote-spy, configure-remote-spy, and get-remote-spy-logs without needing their schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly routes mode changes to 'remote-spy operation=restart' and states prerequisites (active-client, explicit-mutation-approval) plus a verification step (assert-state). It does not spell out when NOT to start a spy at all, but the alternative for the main confusion case is named.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools