Find string VALUES stored in GC tables (runtime string data scan)
find-string-in-tablesSearch live Luau GC tables for string values containing or exactly matching your query to uncover runtime data strings like server responses or dynamic remote names.
Instructions
Walk every live Luau GC table and report each string VALUE that matches query. This is the runtime-DATA complement to find-string-xrefs (which scans closures' bytecode constants): it finds strings that exist as actual table data at this moment — server responses, built-up chat/UI text, dynamically constructed remote names, cached config strings, decoded tokens — which may never appear as a source literal. By default contains=true performs a plain (non-pattern) substring search; set contains=false for exact equality. Each hit is recorded as { table, key, value } where 'table' is the container address (tostring), 'key' is the field (tostring), and 'value' is the matched string truncated to its first 200 characters. Pivot from a hit with read-path-value / write-path-value (or find-table-references to see who owns the container). Each table's pairs() iteration is pcall-guarded so locked/proxy tables never abort the scan; GC objects examined are capped by maxScan and results by limit, with a 'truncated' flag. Requires getgc (falls back from getgc(true) to getgc()). Returns { query, contains, matchCount, scannedObjects, truncated, matches } or { error }. Signature: { query: string, contains: any?, limit: any?, maxScan: any?, threadContext: number? }. Phase: observe; cost=medium; idempotency=read-only. Requires: active-client. Produces: bounded-candidates. Safety: read-only. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum number of matching strings to return (default 150). Hitting this sets truncated=true. | |
| query | Yes | The string to search for among table VALUES, e.g. 'GodMode', 'http', 'BuyItem', a token prefix, or any substring of runtime text. With contains=true (default) any string value containing this matches; with contains=false only string values exactly equal to this match. Case-sensitive, plain text (not a Lua pattern). | |
| maxScan | No | Maximum number of GC objects to examine before stopping (default 40000). Hitting this sets truncated=true. Raise for a deeper sweep at the cost of time; lower if scans are slow. | |
| contains | No | When true (default), match any string value that CONTAINS `query` as a plain substring (string.find with plain=true). When false, require exact string equality. Use exact to pin one specific value. | |
| threadContext | No | Optional Roblox thread identity for this call; omit it to use the server default. |