Force a function to always return a chosen value (MUTATES STATE via hookfunction)
spoof-function-returnReplace a target function's return value with a chosen result to bypass validation checks, without calling the original function.
Instructions
WRITES LIVE GAME STATE — INSTALLS A PERSISTENT GLOBAL HOOK. Replaces a target function with a stub that IGNORES its arguments and ALWAYS returns a value you choose, without ever calling the original. This is the canonical anticheat/validation bypass: make a check like isValid() return true, force a server-config getter to return your value, or stub a paywall test to return false. Distinct from block-function (which makes the target a no-op returning nothing) because here you control the exact return value. WORKFLOW (stateful — survives across tool calls via getgenv().__mcp_spoofReturns, keyed by functionPath): 1. action='start' with functionPath + returnValue — resolves the target, captures the original, installs a stub that returns your value. Returns { started, key, returns }. 2. action='stop' with the same functionPath — restores the original function. Returns { stopped }. CAVEATS: the hook is GLOBAL and PERSISTS until you stop it (or the client restarts). The original is NEVER called while spoofed, so any side effects the real function had will not happen — this can desync state or destabilize the game, and a live function hook CAN TRIP ANTICHEAT. Always stop when done. Requires hookfunction, newcclosure, and getgenv; restoration uses hookfunction(target, original) with a restorefunction fallback. Returns { error } if a capability is missing, the target cannot be resolved, or there is already an active spoof for fetch/stop. Signature: { action: "start" | "stop", functionPath: string?, returnValue: { kind: "string" | "number" | "boolean" | "nil" | "raw", value: string | number | boolean? }?, threadContext: number? }. Phase: act; cost=medium; idempotency=contextual-write. Requires: active-client, resolved-target, explicit-mutation-approval. Produces: structured-result. Verify with: assert-state. Safety: MUTATING; writes live game/client state. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| action | Yes | 'start' installs the return-spoofing stub on functionPath (requires returnValue); 'stop' restores the original function. Use the SAME functionPath for both so they address the same registry entry. | |
| returnValue | No | The value the spoofed function should always return, expressed as a typed argument. | |
| functionPath | No | Luau expression resolving to the function to spoof, e.g. 'getsenv(game.Players.LocalPlayer.PlayerScripts.AntiCheat).isValid' or 'getrawmetatable(game).__index'. Evaluated as `return <functionPath>` and must resolve to a function. REQUIRED for 'start'. For 'stop' it is the registry key identifying which spoof to restore, so it must match the string used at start. | |
| threadContext | No | Optional Roblox thread identity for this call; omit it to use the server default. |