Skip to main content
Glama
okenjioxx

Roblox Executor MCP Server

by okenjioxx

Replace a closure's environment table

set-function-env
Destructive

Writes live game state by changing a Roblox function's global environment via setfenv, resolving the target function and environment expression; confirm=true required.

Instructions

WRITES LIVE GAME STATE. Resolve a function and an environment-table expression, then call setfenv. This changes global lookup behavior for the live closure and requires confirm=true. Signature: { functionPath: string, threadContext: number?, environmentExpression: string, confirm: boolean? }. Phase: act; cost=medium; idempotency=idempotent-write. Requires: active-client, resolved-target, explicit-mutation-approval. Produces: operation-receipt. Verify with: assert-state. Safety: MUTATING; writes live game/client state. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
confirmNoExplicit safety acknowledgement; must be true before this state-changing operation runs.
functionPathYesLuau expression resolving to the target function.
threadContextNoOptional Roblox thread identity for this call; omit it to use the server default.
environmentExpressionYestext value for environment expression.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0-spies.2

TDQS

A3.7/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description adds real behavioral data beyond the annotations: it mutates live game state, alters global lookup semantics for the live closure, requires confirm=true, and requires explicit mutation approval. However, it labels the operation 'idempotency=idempotent-write' while the annotations declare idempotentHint=false, which conflicts on retry-safety for a destructive operation and risks an agent re-running it.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The most important fact ('WRITES LIVE GAME STATE') is front-loaded before any mechanics. The remaining sentences are dense and mostly earn their place, though the templated Phase/cost/idempotency/receipt metadata reads as boilerplate that dilutes the core message.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a destructive, no-output-schema mutation, the description covers what is changed, approval preconditions, the produced operation-receipt, verification via assert-state, and failure guidance pointing to tool-schema. It omits reversibility (there is no undo for a replaced environment) and the exact effect on the previous environment table.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all four fields, including confirm's safety meaning and threadContext's default behavior. The description's signature line merely restates the schema without adding format, constraints, or examples beyond what is already structured, so the baseline of 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a concrete verb+resource: resolve a function and an environment-table expression, then call setfenv, changing global lookup for the live closure. This clearly separates it from read-only siblings like dump-function-env and get-function-env, and from the adjacent set-closure-upvalue/constant tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It names preconditions (active-client, resolved-target, explicit-mutation-approval), the mandatory confirm=true acknowledgement, the acting phase, and a follow-up verification step with assert-state. It stops short of explicitly naming alternatives (e.g., 'inspect first with dump-function-env') or stating when not to use it.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools