Search the GC heap for where a value is stored (Cheat-Engine scan)
search-gc-valueFind where values like coin/HP totals, remote names, toggles, or object references live in Roblox Luau GC memory, then report matching keys, values, constants, and upvalues.
Instructions
Cheat-Engine-style heap scanner: find WHERE a specific value lives across the entire Luau garbage collector. Resolve a target from one of five value types, then walk every live object via getgc(true) and report each place that holds it. For GC TABLES the tool pcall-iterates pairs() and records a hit when a KEY or a VALUE matches (string matches support exact OR 'contains' substring search). For Lua CLOSURES (when scanFunctions is on) it scans the function's constants and upvalues. Each match reports { container, where, keyText? } where 'where' is one of value/key/constant/upvalue and 'container' is the table address or the closure's source:line. Use it to locate a coin/HP total, a remote or flag name, a boolean toggle, or a Part/Instance reference, then pivot with inspect-closure / dump-table / set-closure-upvalue to read or mutate it. Requires getgc; closure scanning additionally requires getconstants/getupvalues (each is type-guarded and simply skipped if the executor lacks it). Everything is pcall-guarded so locked/dead objects never abort the scan; the object count is capped by maxScan and the result list by limit, with a 'truncated' flag. Returns { valueType, matchCount, truncated, matches } or { error }. Signature: { valueType: "number" | "string" | "boolean" | "instance" | "raw", value: string | number | boolean?, match: any?, scanFunctions: any?, limit: any?, maxScan: any?, threadContext: number? }. Phase: observe; cost=medium; idempotency=read-only. Requires: active-client. Capabilities: getgc. Produces: bounded-candidates. Safety: read-only. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Max number of match locations to return (default 150). Hitting this sets truncated=true. | |
| match | No | Match mode (default 'exact'). 'contains' performs a plain (non-pattern) substring search and applies ONLY to string searches; for every other value type it is ignored and exact equality is used. | exact |
| value | No | The value to search for. For number/string/boolean this is the literal value. For 'instance' it is a Luau path expression resolving to an Instance. For 'raw' it is a Luau expression that is evaluated and whose result is the search target. Required for instance/raw; for number/string/boolean it may be omitted only if you really mean to search for the empty string / 0 / false (prefer always supplying it). | |
| maxScan | No | Max number of GC objects (tables + functions) to examine before stopping (default 40000). Hitting this sets truncated=true. Raise for a more thorough sweep at the cost of time; lower it if scans are slow. | |
| valueType | Yes | How to interpret 'value' and what to search for: - 'number': search for a numeric value (e.g. a coin/HP total). - 'string': search for a string (supports match='contains' for substrings — e.g. a remote name). - 'boolean': search for true/false (e.g. a god-mode flag). - 'instance': 'value' is a Luau path/expression resolving to an Instance (e.g. 'game.Workspace.Boss'). - 'raw': 'value' is an arbitrary Luau expression; the tool searches for whatever it evaluates to (e.g. 'Enum.KeyCode.E', 'Vector3.new(0,0,0)', 'game:GetService("Players").LocalPlayer'). | |
| scanFunctions | No | Also scan Lua closures' constants and upvalues for the target (default true). Disable to scan tables only, which is faster and avoids getconstants/getupvalues overhead. | |
| threadContext | No | Optional Roblox thread identity for this call; omit it to use the server default. |