Inspect RemoteFunction / BindableFunction invoke callbacks
inspect-callbacksRetrieve and disassemble invoke callbacks on RemoteFunctions and BindableFunctions, exposing hidden OnClientInvoke, OnServerInvoke, and OnInvoke functions for reverse engineering.
Instructions
Find and disassemble the invoke callbacks bound to RemoteFunctions and BindableFunctions — these are where a game's request/response logic lives (the server-authoritative answer to a client question, or a cross-script RPC), so they are frequently the single most valuable functions to reverse. Unlike signal events (OnClientEvent/OnServerEvent), invoke callbacks are stored as a hidden property on the instance and are NOT visible to getconnections; the ONLY way to retrieve them is getcallbackvalue. This tool walks a subtree (default the whole DataModel), and for every RemoteFunction reads its OnClientInvoke and OnServerInvoke slots, and for every BindableFunction reads its OnInvoke slot. For each slot that actually holds a function it captures debug.info (source / line-defined / name) so you can immediately pivot to inspect-closure, get-closure-constants, get-closure-upvalues, scan-proto-functions, or hook-function on the exact callback. Use the source/line to locate the defining script and the name to understand intent. Requires getcallbackvalue (returns a clean { error } if the executor lacks it). The scan is fully pcall-guarded (locked/parented-out/dead instances never abort it), capped by maxScan, and the output is capped by limit with a truncated flag. Read-only: it inspects callbacks but never invokes or modifies them. Returns { count, scanned, truncated, root, callbacks } where each entry is { remote, class, slot, callback = { source, line, name, pointer, isC } }. Signature: { root: any?, limit: any?, maxScan: any?, threadContext: number? }. Phase: observe; cost=medium; idempotency=read-only. Requires: active-client. Produces: structured-observation, operation-receipt. Safety: read-only. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| root | No | Luau expression for the subtree root whose descendants are scanned, evaluated as `return <root>`. Defaults to 'game' (the whole DataModel). Narrow it to cut scan time and noise, e.g. 'game.ReplicatedStorage', 'game:GetService("ReplicatedStorage").Remotes', or 'game.Players.LocalPlayer.PlayerGui'. | game |
| limit | No | Maximum number of callback entries to return (default 150). Once reached the scan stops early and `truncated` is set true. | |
| maxScan | No | Maximum number of descendant instances to visit while scanning (default 8000). Caps cost on huge DataModels; if hit, `truncated` is set true. Clamped to 100..60000. | |
| threadContext | No | Optional Roblox thread identity for this call; omit it to use the server default. |