Skip to main content
Glama
okenjioxx

Roblox Executor MCP Server

by okenjioxx

Inspect RemoteFunction / BindableFunction invoke callbacks

inspect-callbacks
Read-onlyIdempotent

Retrieve and disassemble invoke callbacks on RemoteFunctions and BindableFunctions, exposing hidden OnClientInvoke, OnServerInvoke, and OnInvoke functions for reverse engineering.

Instructions

Find and disassemble the invoke callbacks bound to RemoteFunctions and BindableFunctions — these are where a game's request/response logic lives (the server-authoritative answer to a client question, or a cross-script RPC), so they are frequently the single most valuable functions to reverse. Unlike signal events (OnClientEvent/OnServerEvent), invoke callbacks are stored as a hidden property on the instance and are NOT visible to getconnections; the ONLY way to retrieve them is getcallbackvalue. This tool walks a subtree (default the whole DataModel), and for every RemoteFunction reads its OnClientInvoke and OnServerInvoke slots, and for every BindableFunction reads its OnInvoke slot. For each slot that actually holds a function it captures debug.info (source / line-defined / name) so you can immediately pivot to inspect-closure, get-closure-constants, get-closure-upvalues, scan-proto-functions, or hook-function on the exact callback. Use the source/line to locate the defining script and the name to understand intent. Requires getcallbackvalue (returns a clean { error } if the executor lacks it). The scan is fully pcall-guarded (locked/parented-out/dead instances never abort it), capped by maxScan, and the output is capped by limit with a truncated flag. Read-only: it inspects callbacks but never invokes or modifies them. Returns { count, scanned, truncated, root, callbacks } where each entry is { remote, class, slot, callback = { source, line, name, pointer, isC } }. Signature: { root: any?, limit: any?, maxScan: any?, threadContext: number? }. Phase: observe; cost=medium; idempotency=read-only. Requires: active-client. Produces: structured-observation, operation-receipt. Safety: read-only. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
rootNoLuau expression for the subtree root whose descendants are scanned, evaluated as `return <root>`. Defaults to 'game' (the whole DataModel). Narrow it to cut scan time and noise, e.g. 'game.ReplicatedStorage', 'game:GetService("ReplicatedStorage").Remotes', or 'game.Players.LocalPlayer.PlayerGui'.game
limitNoMaximum number of callback entries to return (default 150). Once reached the scan stops early and `truncated` is set true.
maxScanNoMaximum number of descendant instances to visit while scanning (default 8000). Caps cost on huge DataModels; if hit, `truncated` is set true. Clamped to 100..60000.
threadContextNoOptional Roblox thread identity for this call; omit it to use the server default.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0-spies.2

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover the read-only/idempotent profile, but the description adds substantial context beyond them: requires getcallbackvalue (clean { error } otherwise), fully pcall-guarded so dead/parented-out instances never abort, capped by maxScan, output capped by limit with a truncated flag, and an explicit 'never invokes or modifies' guarantee. This is rich behavioral disclosure.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the purpose and the key 'why it matters' clause before mechanics. It is dense and long, and the trailing 'Signature/Phase/cost/idempotency' line partially duplicates annotations, but nearly every sentence carries actionable detail and little is truly wasted.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description compensates by spelling out the return shape { count, scanned, truncated, root, callbacks } and each entry's fields (remote, class, slot, callback = { source, line, name, pointer, isC }), plus failure behavior. Nothing an agent needs to call and interpret it is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents root, limit, maxScan, and threadContext with defaults and clamps. The description only restates root's default (whole DataModel) and the limit/maxScan caps, adding marginal meaning over the schema; baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource ('Find and disassemble the invoke callbacks bound to RemoteFunctions and BindableFunctions') and immediately distinguishes them from signal events, which an agent can tell apart from siblings like get-connection-info or find-instances-with-connections without opening a schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly explains why and when to reach for it: invoke callbacks hold request/response logic and are 'frequently the single most valuable functions to reverse', and it notes they are NOT visible to getconnections so getcallbackvalue is the only retrieval path. It also names the downstream pivots (inspect-closure, get-closure-constants, hook-function, scan-proto-functions).

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools