exploit-security-specialist

exploit-security-specialist is an agent for Claude Code from CodePhobiia/claude-roblox-game-studio. It costs 54 tokens per session (1,168 once invoked), scanned A, original, MIT.

A Roblox security specialist focused on finding and reducing cheats, vulnerabilities, and abuse in game code and network messages.

In plain words
What is it for?
Use it to design anti-cheat systems, audit existing code, validate actions on the server, limit request rates, check data types and values, and document security issues.
Why use it?
It helps protect games from movement cheats, item duplication, forged requests, and excessive remote-message use.

Agent for Claude Code

Written for Claude Code: installed under .claude/. Also seen: model in frontmatter.

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/codephobiia/claude-roblox-game-studio/exploit-security-specialist
Clone the repo
git clone --depth 1 https://github.com/CodePhobiia/claude-roblox-game-studio

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for exploit-security-specialist

README.md
[![agentmods](https://agentmods.dev/badge/agents/codephobiia/claude-roblox-game-studio/exploit-security-specialist.svg)](https://agentmods.dev/agents/codephobiia/claude-roblox-game-studio/exploit-security-specialist)
Your own site
<a href="https://agentmods.dev/agents/codephobiia/claude-roblox-game-studio/exploit-security-specialist"><img src="https://agentmods.dev/badge/agents/codephobiia/claude-roblox-game-studio/exploit-security-specialist.svg" alt="Measured on agentmods" height="20"></a>
Per session 54 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 1,168 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00054 $0.01168
Opus 5 $0.00027 $0.00584
Sonnet 5 $0.00011 $0.00234
Haiku 4.5 $0.00005 $0.00117

Measured 5d ago against content hash 87d6f4ed8646, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

exploit-security-specialist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/exploit-security-specialist.md · 111 lines

How it starts

The opening of the file, as written. The whole thing — 111 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are the Exploit & Security Specialist for a Roblox project. You identify and mitigate security vulnerabilities.

Your Domain

  • Anti-exploit system design
  • Security auditing of existing code
  • Common Roblox exploit vector identification
  • Server-side validation enforcement
  • Client-side sanity checks (as backup, never primary)
  • Exploit report documentation

Common Roblox Exploit Vectors

Movement Exploits

  • Speed hack: Client moves faster than allowed
  • Teleport hack: Client sets CFrame to arbitrary position
  • Fly hack: Client removes gravity/collision
  • Noclip: Client passes through walls
  • Mitigation: Server-side position validation with tolerance, speed checks per frame, teleport distance limits, HumanoidRootPart.CFrame monitoring, anchor on detection

Remote Exploits

  • Remote spam: Firing remotes at extreme rates
  • Argument spoofing: Sending invalid types/values through remotes
  • Remote sniffing: Reading remote names and reverse-engineering the API
  • Mitigation: Rate limiting, type validation, sanity checks, obfuscated remote names (optional)

Economy Exploits

  • Item duplication: Exploiting race conditions in trading/DataStore saves
  • Negative purchase: Sending negative quantities to gain items
  • Transaction replay: Replaying a purchase remote
  • Mitigation: Session locking, server-side transaction validation, atomic operations, unique transaction IDs

Memory/Data Exploits

  • LocalScript injection: Running arbitrary code on the client (via exploit tools like Synapse)
  • Memory editing: Changing local values (health, speed, etc.)
  • Mitigation: Client values are display-only; server is authoritative for ALL game state

DataStore Exploits

  • Save spam: Force repeated saves to exhaust budget
  • Session hijack: Fake session to duplicate data across servers
  • BindToClose skip: Exploit shutdown timing to skip save
  • Mitigation: Session locking with server JobId, BindToClose with timeout, save rate limit

Read the full file on GitHub · 111 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 111 lines · 54 tokens per session scan A 87d6f4ed8646

Subscribe to this mod's changes

exploit-security-specialist is an agent published in the GitHub repository CodePhobiia/claude-roblox-game-studio (9 stars, last pushed 4mo ago), licensed MIT. It adds 54 tokens to every session and 1,168 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

technical-director

The Technical Director owns all high-level technical decisions including engine architecture, technology choices, performance strategy, and technical risk management. Use this agent for architecture-level decisions, technology evaluations, cross-system technical conflicts, and when a technical choice will constrain or…

Donchitos/Claude-Code-Game-Studios · 56 tokens

pixel-art-animation-reviewer

Independent reviewer of pixel-art ANIMATION quality (loop seamlessness, motion physics, multi-component motion, frame timing, period selection, particle determinism). One of four specialized review roles in the pixel-art-quality-board orchestrator. Use when the user asks to "check animation timing", "verify loop…

AnastasiyaW/codex-claude-code-config · 140 tokens

godot-game-dev

Use this agent when the user needs help implementing Godot Engine features, including GDScript or C# coding, scene/node setup, player controllers, enemy AI, inventory systems, dialogue, save/load, HUD, cameras, multiplayer, or any Godot-specific implementation. Examples: Context: User needs to implement enemy AI.…

jame581/GodotPrompter · 357 tokens

ai-programmer

Implements NPC behavior, navigation, decision systems, and AI support tooling.

MRCalderon3D/everything-game-dev-code · 19 tokens

game-engine-architect

Specialized game engine architect with expertise in engine architecture, rendering systems, and game physics. Use when designing game engines, implementing core engine systems, or optimizing engine performance.

TheBushidoCollective/han · 39 tokens

game-tools-engineer

Use when building game development tools, editors, asset pipelines, build systems, and workflow automation. Expert in tooling that multiplies team productivity.

TheBushidoCollective/han · 34 tokens