Find hidden Remote / Bindable channels
find-hidden-remotesDetect nil-parented or detached remote and bindable instances outside the game tree to expose hidden backdoor or data-exfiltration channels for inspection.
Instructions
Find RemoteEvent / RemoteFunction / UnreliableRemoteEvent / BindableEvent / BindableFunction instances that are NOT in the normal game tree — i.e. nil-parented or detached from the DataModel. A remote/bindable kept alive by a reference but hidden off the hierarchy is a classic backdoor / data-exfiltration channel: an exploit or malicious script fires it to phone home or to receive commands without the object ever appearing in the Explorer. This tool pulls getnilinstances() (the primary source of nil-parented objects) and, when getinstances() is available, also includes any remote/bindable that is not a descendant of game, deduping across both sources. It complements get-nil-instances / find-hidden-instances by narrowing to just the communication-channel classes and giving a ready-to-inspect list. Returns { count, byClass, truncated, samples: [{ class, name, location }] }, capped. Requires getnilinstances; getinstances is used additionally when present. Degrades with a clear error if neither is available. Signature: { limit: any?, maxScan: any?, threadContext: number? }. Phase: observe; cost=medium; idempotency=read-only. Requires: active-client. Produces: bounded-candidates. Safety: read-only. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max number of detailed sample remotes/bindables to return in the samples list (default 200, clamped to 2000). The count and byClass tally always cover every hidden remote/bindable found regardless of this limit. | |
| maxScan | No | Max number of instances to examine from getinstances() before stopping the getinstances pass (default 60000, clamped to 500000). Protects against huge games; if hit, `truncated` is set true. The getnilinstances pass is always fully scanned. | |
| threadContext | No | Optional Roblox thread identity for this call; omit it to use the server default. |