Skip to main content
Glama
okenjioxx

Roblox Executor MCP Server

by okenjioxx

Force a function to always return a chosen value (MUTATES STATE via hookfunction)

spoof-function-return
Destructive

Replace a target function's return value with a chosen result to bypass validation checks, without calling the original function.

Instructions

WRITES LIVE GAME STATE — INSTALLS A PERSISTENT GLOBAL HOOK. Replaces a target function with a stub that IGNORES its arguments and ALWAYS returns a value you choose, without ever calling the original. This is the canonical anticheat/validation bypass: make a check like isValid() return true, force a server-config getter to return your value, or stub a paywall test to return false. Distinct from block-function (which makes the target a no-op returning nothing) because here you control the exact return value. WORKFLOW (stateful — survives across tool calls via getgenv().__mcp_spoofReturns, keyed by functionPath): 1. action='start' with functionPath + returnValue — resolves the target, captures the original, installs a stub that returns your value. Returns { started, key, returns }. 2. action='stop' with the same functionPath — restores the original function. Returns { stopped }. CAVEATS: the hook is GLOBAL and PERSISTS until you stop it (or the client restarts). The original is NEVER called while spoofed, so any side effects the real function had will not happen — this can desync state or destabilize the game, and a live function hook CAN TRIP ANTICHEAT. Always stop when done. Requires hookfunction, newcclosure, and getgenv; restoration uses hookfunction(target, original) with a restorefunction fallback. Returns { error } if a capability is missing, the target cannot be resolved, or there is already an active spoof for fetch/stop. Signature: { action: "start" | "stop", functionPath: string?, returnValue: { kind: "string" | "number" | "boolean" | "nil" | "raw", value: string | number | boolean? }?, threadContext: number? }. Phase: act; cost=medium; idempotency=contextual-write. Requires: active-client, resolved-target, explicit-mutation-approval. Produces: structured-result. Verify with: assert-state. Safety: MUTATING; writes live game/client state. On failure: inspect tool-schema for exact fields, defaults, constraints, and an invocation example.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
actionYes'start' installs the return-spoofing stub on functionPath (requires returnValue); 'stop' restores the original function. Use the SAME functionPath for both so they address the same registry entry.
returnValueNoThe value the spoofed function should always return, expressed as a typed argument.
functionPathNoLuau expression resolving to the function to spoof, e.g. 'getsenv(game.Players.LocalPlayer.PlayerScripts.AntiCheat).isValid' or 'getrawmetatable(game).__index'. Evaluated as `return <functionPath>` and must resolve to a function. REQUIRED for 'start'. For 'stop' it is the registry key identifying which spoof to restore, so it must match the string used at start.
threadContextNoOptional Roblox thread identity for this call; omit it to use the server default.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv2.0.0-spies.2

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare destructiveHint=true and non-idempotent, but the description adds substantial context beyond them: the hook is GLOBAL and persists until stopped, the original is never called so side effects are lost, state can desync, and live hooks can trip anticheat. It also documents the registry mechanism (getgenv().__mcp_spoofReturns keyed by functionPath) and error return shapes.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core mutating purpose and caveats before the workflow and metadata. It is dense and the signature/metadata tail partially duplicates the schema, but the ordering is logical and most sentences carry real information.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description explicitly documents the return shapes ({ started, key, returns }, { stopped }, { error }) and failure conditions. Combined with the safety, workflow, and capability requirements, an agent has everything needed to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents action, returnValue/kind/value, functionPath, and threadContext in detail. The description reinforces the functionPath-as-registry-key semantics and repeats the signature, but adds little that the schema does not already state, so the baseline 3 applies.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource (installs a persistent return-spoofing hook on a target function) and explicitly contrasts with the sibling block-function, explaining the exact behavioral difference (controlled return value vs no-op). An agent can distinguish this from related hook tools without opening any schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives an explicit step-by-step workflow for action='start' vs 'stop', names the sibling alternative it is not, and instructs 'Always stop when done.' Prerequisites (active-client, resolved-target, explicit-mutation-approval) and the correct usage sequence are spelled out rather than inferred.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools