Skip to main content
Glama
okenjioxx

Roblox Executor MCP Server

by okenjioxx

Replace an object's raw metatable (MUTATES live state)

set-rawmetatable
Destructive

Replace a live Roblox object's entire metatable, bypassing __metatable locks, to swap __index or __namecall methods and alter runtime behavior.

Instructions

WRITES LIVE GAME STATE. DANGER — Resolve a Luau expression to an object (table/Instance/userdata) and REPLACE its entire metatable via setrawmetatable, bypassing any __metatable lock. This swaps out __index/__namecall/__newindex etc. wholesale, so it can completely change how the object behaves — overwriting the game's core metatable can break the client, sever security routing, and is a strong anticheat signal. Typical RE use: clone the existing metatable, modify a metamethod, then set it back. Note the target metatable may need to be writable (see set-metatable-readonly) before this succeeds. This changes the live runtime in place. Requires setrawmetatable. Because it mutates state you MUST pass confirm=true; otherwise the tool refuses and does nothing. Returns { Target, ok } or { error }. Signature: { objectPath: string, metatableExpr: string, confirm: boolean, threadContext: number? }. Phase: act; cost=medium; idempotency=idempotent-write. Requires: active-client, resolved-target, explicit-mutation-approval. Capabilities: getrawmetatable. Produces: operation-receipt. Verify with: assert-state. Safety: MUTATING; writes live game/client state. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
confirmYesSafety gate. Must be exactly true to apply the change. If omitted or false the tool refuses and does nothing, because replacing a live object's metatable can break the game or trip anticheat.
objectPathYesLuau expression resolving to the object whose metatable you want to replace, e.g. 'game', 'game.Players.LocalPlayer', or 'getgenv().SomeProxy'. Evaluated as `return <objectPath>`.
metatableExprYesRaw Luau expression evaluating to the NEW metatable (a table) to install, e.g. '{ __index = function() return nil end }', 'setmetatable({}, nil)', or a previously cloned/edited table referenced from getgenv(). Evaluated as `return <metatableExpr>`; must resolve to a table or nil.
threadContextNoOptional Roblox thread identity for this call; omit it to use the server default.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0-spies.2

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Goes well beyond annotations (destructiveHint=true, readOnlyHint=false, idempotentHint=false) by naming the concrete mechanics: bypasses __metatable lock, swaps __index/__namecall/__newindex wholesale, can break the client, severs security routing, is an anticheat signal, and requires confirm=true or it refuses. Also discloses the return shape { Target, ok } / { error }. Minimal tension: the trailing 'idempotency=idempotent-write' sits awkwardly against idempotentHint=false, but this is a labeling nuance, not a safety contradiction.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the danger and the core action, and most sentences carry distinct information (mechanics, risk, RE workflow, confirm gate, return values). The trailing metadata block (Phase/cost/idempotency/Requires/Capabilities/Produces/Verify/On failure) is dense but partly redundant with structured fields, keeping it from a 5.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite no output schema, the description states the return shape, the mandatory confirm gate, prerequisites (setrawmetatable, writable target, resolved target), and failure behavior. For a destructive live-state mutation tool, an agent has everything needed to invoke it correctly and safely.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all four parameters with examples and the confirm safety gate. The description's inline signature and confirm restatement add little beyond the schema. Baseline 3 is appropriate when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource: resolve a Luau expression to an object and REPLACE its entire metatable via setrawmetatable, bypassing any __metatable lock. This is clearly distinguishable from siblings like get-metatable, inspect-instance-metatable, hook-metamethod, and set-metatable-readonly. An agent knows exactly what this does versus neighbors.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives a concrete when-to-use pattern ('clone the existing metatable, modify a metamethod, then set it back') and a prerequisite chain (target metatable may need to be writable — see set-metatable-readonly; requires setrawmetatable). It stops short of naming an explicit alternative to prefer for lighter-touch cases (e.g. hook-metamethod), so it is strong context without full when-not routing.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools