Skip to main content
Glama
okenjioxx

Roblox Executor MCP Server

by okenjioxx

Find xrefs to a string (IDA xref-to-string)

find-string-xrefs
Read-onlyIdempotent

Cross-reference a string across Luau functions to find every function whose bytecode contains it, pivoting from remote names, URLs, or error messages to the code that references them.

Instructions

Cross-reference a string the way IDA jumps from a string literal to every place it is used. Walks every Luau function in the GC and reports each function that has the query as a string constant in its bytecode — i.e. each function that likely produces or compares against that text. Use exact=true for an exact match, otherwise it does a plain substring search (case-sensitive). Each hit reports the owning script source, line, function name and pointer, plus the first matching constant. Great for pivoting from list-strings to the code that references a remote name, URL, error message, or anti-cheat tag. Requires getgc + getconstants; caps the scan and flags truncation. Signature: { query: string, exact: any?, limit: any?, maxScan: any?, threadContext: number? }. Phase: observe; cost=medium; idempotency=read-only. Requires: active-client. Produces: bounded-candidates. Safety: read-only. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
exactNoIf true, only match constants that equal the query exactly. If false (default), match any constant that contains the query as a substring (case-sensitive).
limitNoMax matching functions to return (default 100).
queryYesThe string to cross-reference (e.g. a remote name, URL, or error message).
maxScanNoMax GC functions to scan (default 9000).
threadContextNoOptional Roblox thread identity for this call; omit it to use the server default.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0-spies.2

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly/idempotent/non-destructive, so the safety profile is covered. The description still adds real behavioral context beyond them: the GC-walking scan, the getgc + getconstants dependencies, and the fact that the scan is capped and truncation is flagged. It never contradicts the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The purpose and search semantics are front-loaded well, but the trailing block ('Signature: {...}. Phase: observe; cost=medium; idempotency=read-only. Requires: active-client... Safety: read-only. On failure: inspect tool-schema...') largely repeats the schema and annotations and does not earn its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With annotations, a 100%-covered schema, and no output schema, the description is nearly complete: it describes the return payload (owning script source, line, function name, pointer, first matching constant) and the truncation flag, plus the active-client prerequisite. Minor boilerplate aside, an agent has what it needs to call it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the schema already documents exact, limit, maxScan, and threadContext. The description restates the exact/substring behavior and the scan caps without adding syntax or constraints the schema lacks, which lands at the baseline for full-coverage schemas.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The definition states a precise verb+resource ('Cross-reference a string... reports each function that has the query as a string constant in its bytecode') and gives a concrete mechanism (walks every Luau function in the GC). It implicitly separates itself from list-strings by framing the tool as the pivot step after listing, and from find-constants-xref/find-function-xrefs by scoping to string constants. An agent can tell what this does without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It gives clear usage context ('Great for pivoting from list-strings to the code that references a remote name, URL, error message, or anti-cheat tag') and the exact-vs-substring condition for the exact parameter. It does not, however, name a sibling to prefer or state an explicit when-not-to-use condition, so it stops short of full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools