Audit script execution footprint and local detection exposure
execution-footprint-auditAudit local Luau execution exposure read-only: resolve scripts or closures without invoking them, inventory virtual-input references, and return risk findings and evidence.
Instructions
READ-ONLY, one-shot Luau auditor for local execution exposure. It resolves an optional script and/or closure without invoking it; inventories virtual-input globals and VirtualInputManager/VirtualUser references; distinguishes direct Instance references from cloneref-like alternate references when compareinstances exists; compares input functions with retained MCP closure handles; audits bounded getsenv/getfenv key-name leaks; classifies closure origin/hash/hook state; scans bounded source/constants for input, environment, debug, and hook indicators; and returns findings, unknown checks, confidence, risk score, privacy-safe evidence, and truncation telemetry. It never sends input, calls the target closure, walks getgc/descendants, installs hooks, or writes to game objects or script values. A clean result does NOT prove that server-side or external detection did not occur, and cloneref/clone matches are provenance only—not an undetectability guarantee. Signature: { scriptPath: string?, functionPath: string?, includeSourceScan: any?, includeStackEnvironments: any?, maxStackFrames: any?, maxEvidence: any?, maxEnvironmentKeys: any?, maxSourceChars: any?, maxConstants: any?, maxUpvalues: any?, threadContext: number? }. Phase: verify; cost=medium; idempotency=read-only. Requires: active-client, resolved-target. Produces: diagnostic-report. Safety: read-only. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| scriptPath | No | Optional Luau expression resolving to the LocalScript or ModuleScript to audit. | |
| maxEvidence | No | Hard cap for findings and source/constant evidence records. | |
| maxUpvalues | No | Maximum target-closure upvalues classified without returning captured values. | |
| functionPath | No | Optional Luau expression resolving to a function/closure to audit without invoking it. | |
| maxConstants | No | Maximum target-closure constants inspected internally. | |
| threadContext | No | Optional Roblox thread identity for this call; omit it to use the server default. | |
| maxSourceChars | No | Maximum script.Source characters scanned; the report says when this truncates. | |
| maxStackFrames | No | Maximum current auditor stack levels inspected with getfenv (0 disables stack probing). | |
| includeSourceScan | No | Read and scan a bounded script.Source prefix when the property is accessible. | |
| maxEnvironmentKeys | No | Maximum key names retained from each unique environment. | |
| includeStackEnvironments | No | Inspect key names from a bounded number of the auditor's current getfenv stack frames. |