Lightweight anti-cheat surface summary
get-anticheat-surfacesSummarizes observable anti-cheat surfaces: Heartbeat/Stepped connection counts, locked game metatable, nil-parented instances, and suspicious globals. Read-only.
Instructions
Fast, lightweight defensive recon that summarizes the most common anti-cheat surfaces WITHOUT a heavy GC walk (complements, and does not duplicate, the deeper scan-hook-surfaces tool). It checks: (1) how many connections are attached to RunService's Heartbeat, Stepped, and RenderStepped — the signals anti-cheats most often use for per-frame validation loops — via getconnections; (2) whether game's raw metatable is locked (isreadonly on getrawmetatable(game)), which gates __index/__namecall hooking; (3) the count of nil-parented instances (getnilinstances), where detached watchdog scripts/objects often hide; and (4) any getgenv() global names that look anti-cheat-related (matching detect/ban/kick/anticheat/flag/cheat, case-insensitive), which can reveal an exploit's own loader or a leaked server-side guard name. Use this only as lightweight ambient context after execution-footprint-audit; it reports observable surfaces and does not prove detection or provide concealment. Each probe degrades gracefully and is pcall-guarded; missing executor functions are reported as unavailable rather than failing the call. Returns { runServiceConnections, gameMetatableReadonly, nilInstanceCount, suspiciousGlobals, notes } or { error }. Signature: { threadContext: number? }. Phase: observe; cost=medium; idempotency=read-only. Requires: active-client. Produces: structured-observation, diagnostic-report. Safety: read-only. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| threadContext | No | Optional Roblox thread identity for this call; omit it to use the server default. |