Skip to main content
Glama
okenjioxx

Roblox Executor MCP Server

by okenjioxx

Execute a Luau file on the active client

execute-file
Destructive

Run a Luau script file from allow-listed server paths on the active Roblox client, returning its first decoded result.

Instructions

Read a Luau script from the SERVER host filesystem and execute its contents on the active Roblox client, returning the first value the script returns (decoded automatically — return what you want back). The path is read through an allow-list sandbox: only files inside the configured roots (the server's working directory, ~/Documents, and any extra script directories set in the config) can be read, and symlinks that escape those roots are rejected. A path outside the allow-list, or a missing file, returns an error without running anything. Use run-luau when you already have the source inline. Signature: { path: string, threadContext: number?, timeoutMs: number? }. Phase: act; cost=medium; idempotency=contextual-write. Requires: active-client, resolved-target, explicit-mutation-approval. Produces: operation-receipt. Verify with: assert-state. Safety: MUTATING; writes executor workspace filesystem. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pathYesAbsolute or relative path to a .lua/.luau file inside an allow-listed root.
timeoutMsNoPer-call deadline in milliseconds. Server default if omitted.
threadContextNoRoblox thread identity to run under (e.g. 2 = game scripts, 8 = elevated). Server default if omitted.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0-spies.2

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond the annotations: describes the allow-list sandbox (configured roots, symlink escape rejection), that out-of-allow-list or missing files error without running anything, that the return value is auto-decoded, and the MUTATING safety profile and operation-receipt output. This enriches the destructiveHint=true annotation rather than merely restating it.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core read-execute-return behavior, then constraint and routing details. Some material is boilerplate envelope (Phase/cost/idempotency/Signature) that partly duplicates structured fields, but nothing is truly wasted and the ordering serves the agent.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, yet the description explains the return value (first decoded return value) and the error path. Combined with requires/produces/verify and safety notes, an agent has enough to call and verify this mutating executor correctly, so nothing material is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already defines path, timeoutMs, and threadContext semantics; the description's signature listing is redundant. It does add meaningful constraint for `path` via the allow-list root/symlink rules and notes 'return what you want back' for the return value, so it slightly exceeds the baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States specific verbs and resources: read a Luau file from the SERVER host filesystem and execute its contents on the active Roblox client, returning the first decoded value. It explicitly contrasts with the sibling run-luau by describing the file-vs-inline distinction, so an agent can distinguish it without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly routes between alternatives: 'Use run-luau when you already have the source inline,' and this tool when the source is a file. It also names prerequisites (active-client, resolved-target, explicit-mutation-approval) and the verify step (assert-state), giving clear when-to-use context.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools