SkillAgentSearch skills...

Tripwire

Agentic MCP for Roblox. Run tests and find exploits in your game from Claude Code, Codex, or Gemini.

Install / Use

claude mcp add aliboIly -- npx -y github:aliboIly/Tripwire

If the server publishes to npm under a different name, use that package instead — check the repo README.

About this skill
🔌

MCP Server

Model Context Protocol server

Quality Score

80/100

Category

Security

Supported Platforms

Claude Code
Claude Desktop
Gemini CLI
OpenAI Codex

Our assessment of Tripwire

Tripwire scores 80/100 on our quality scale, 642nd of 790 Security skills we index.

Its MCP Server is 23 KB long, well organised into 27 sections with 9 code examples: a thorough specification that gives an agent plenty to work with.

It has 3 GitHub stars, so there is little community track record yet; judge it on its content.

Substance
30/30
Structure
20/20
Description
12/15
Adoption
3/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 35 days ago, so Tripwire is actively maintained.
  • Our last check on 2026-09-18 found the source still online.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.

Automated pattern scan on 2026-09-29. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

Tripwire compared with similar skills

All 4 of these similar skills score higher than Tripwire; compare them before choosing.

SkillScoreStarsUpdatedFormat
Tripwire (this skill)by aliboIly80335d agoMCP Server
Agent-Reachby Panniantong10086.0k13d agoCLAUDE.md
headroomby headroomlabs-ai10074.0ktodayCLAUDE.md
rufloby ruvnet10073.4ktodayCLAUDE.md
CowAgentby zhayujie10047.2ktodayCLAUDE.md

Frequently asked questions

How do I install Tripwire?
Run claude mcp add aliboIly -- npx -y github:aliboIly/Tripwire. The install tabs above show the steps for each supported agent.
Which AI agents does Tripwire work with?
It is written for Claude Code, Claude Desktop, Gemini CLI and OpenAI Codex, as a MCP Server file. Other agents that read the same format can often use it too.
Is Tripwire safe to use?
Our scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is Tripwire still maintained?
The repository was last updated 35 days ago, so Tripwire is actively maintained.
<div align="center">

Tripwire

made by alibolly

npm CI MCP Registry License: MIT

An MCP server that gives an AI coding agent real control of Roblox Studio and Roblox Open Cloud, with a test-and-security layer no other Studio MCP has.

</div>

Tripwire lets an assistant read, write, and edit the data model, drive playtests with simulated input, run tests-as-code headlessly in the real engine, flag client-trust exploits in game code, and call the Open Cloud APIs (DataStores, MessagingService, Memory Stores, and more). The Studio tools need no API key; the headless test, asset, and Open Cloud tools use an Open Cloud key.


Requirements

  • An MCP client: Claude Code, Codex, Gemini, or any client that speaks MCP over stdio.
  • Roblox Studio, for the Studio tools. These need no API key.
  • Node.js, only if you run the server with npx. The prebuilt binary needs no Node.
  • For the headless test, asset, and Open Cloud tools: a published place and a Roblox Open Cloud API key. See Open Cloud setup.

Quickstart

Tripwire is for Roblox developers who drive Studio through an AI coding agent.

  1. Wire the server into your MCP client (one command or a small config block, see Install below).
  2. Install the Studio plugin so the Studio tools can reach Studio (see the plugin step in Install).
  3. Open your place in Studio, turn on Game Settings > Security > Allow HTTP Requests, then click the Tripwire toolbar button and press Connect in the panel. The panel shows Connected and the Output prints [Tripwire v...] connected.
  4. Ask your agent to run studio_status. A connected Studio confirms the bridge works.
  5. Optional: add an Open Cloud key for the headless test, asset, and Open Cloud tools (see Open Cloud setup).

Install

Tripwire's server is a single binary. The easiest way to run it is with npx, which fetches the prebuilt binary for your platform, so there is no Rust toolchain to install. Prefer a manual binary or a source build? See the Alternatives at the end of this section.

<details> <summary><b>Claude Code</b></summary>

One command:

claude mcp add --transport stdio tripwire -- npx -y tripwire-roblox

Or add it to a project .mcp.json (or ~/.claude.json):

{
  "mcpServers": {
    "tripwire": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "tripwire-roblox"]
    }
  }
}
</details> <details> <summary><b>Codex</b></summary>

Add to ~/.codex/config.toml:

[mcp_servers.tripwire]
command = "npx"
args = ["-y", "tripwire-roblox"]

Or: codex mcp add tripwire -- npx -y tripwire-roblox

</details> <details> <summary><b>Gemini</b></summary>

Add to ~/.gemini/settings.json (or a project .gemini/settings.json):

{
  "mcpServers": {
    "tripwire": {
      "command": "npx",
      "args": ["-y", "tripwire-roblox"]
    }
  }
}

Or: gemini mcp add tripwire npx -y tripwire-roblox

</details> <details> <summary><b>Other MCP clients</b></summary>

Any client that speaks MCP over stdio can run it:

command: npx
args:    ["-y", "tripwire-roblox"]
</details> <details> <summary><b>Alternatives: prebuilt binary, or build from source</b></summary>

Prebuilt binary (no Node). Download the archive for your platform from the Releases page (for example tripwire-server-vX.Y.Z-aarch64-apple-darwin.tar.gz), extract it, and point your client's command at the extracted tripwire-server with empty args.

Build from source (needs Rust):

git clone https://github.com/aliboIly/Tripwire.git
cd Tripwire/server
cargo build --release   # produces server/target/release/tripwire-server

Then point your client's command at that binary path.

</details> <details> <summary><b>Studio plugin (required for the Studio tools)</b></summary>

The Studio tools reach Studio through a small plugin that long-polls the local server. Grab Tripwire.rbxmx from the Releases page, or build it:

cd Tripwire/plugin
npm install
npx rbxtsc
rojo build --output Tripwire.rbxmx
cp Tripwire.rbxmx ~/Documents/Roblox/Plugins/   # macOS; Windows: %LOCALAPPDATA%\Roblox\Plugins

Restart Studio, enable Game Settings > Security > Allow HTTP Requests, then click the Tripwire toolbar button and press Connect in the panel. The panel shows Connected and the Output prints [Tripwire v...] connected.

</details> <details> <summary><b>Open Cloud key (for headless tests, assets, and Open Cloud tools)</b></summary>

The Studio tools need no key. The Open Cloud tools do. See Open Cloud setup below for the full walkthrough.

</details>

Open Cloud setup

Most of Tripwire needs no credentials. These tools do, because they call Roblox Open Cloud: run_luau, the headless tests (run_tests, run_test_file, list_tests), upload_asset, publish_place, and the DataStore, Ordered DataStore, MessagingService, Memory Store, platform, and engagement tools. They authenticate with a Roblox Open Cloud API key.

Use at your own risk. An Open Cloud key is a real credential with real power over your experience. Depending on the scopes you grant it, it can read and overwrite your live DataStores, publish new versions of your place, upload assets to your account, and message your servers. Treat it like a password: grant only the scopes you actually use, restrict it to your own IP, never commit it, and revoke it if it leaks. You are responsible for what you do with it. Tripwire is not affiliated with or endorsed by Roblox.

1. Create the key

  1. Go to create.roblox.com/dashboard/credentials and sign in.
  2. Click Create API Key and name it (for example Tripwire).
  3. Under Access Permissions, add only the API systems for the tools you want, and grant each the operation it needs, scoped to your experience:
    • Luau Execution (write): run_luau and the headless tests.
    • universe-places (write): publish_place.
    • Assets (read + write): upload_asset.
    • DataStores and Ordered DataStores: the data-store tools.
    • Messaging Service (publish) and Memory Stores: those tools.
    • User/Group/Inventory/Subscription/Notification: the platform and engagement tools.
  4. Under Security, set Accepted IP Addresses to your machine's IP, or 0.0.0.0/0 to allow any (simplest for local use). Set an expiration if you want.
  5. Click Save & Generate Key and copy the key string. It is shown only once.

2. Find your universe and place IDs

In the Studio command bar (View, then Command Bar), run:

print("universe", game.GameId, "place", game.PlaceId)

GameId is your ROBLOX_UNIVERSE_ID; PlaceId is your ROBLOX_PLACE_ID. The place must be published to Roblox for Open Cloud to act on it.

3. Give Tripwire the credentials

Create a .env at the repo root. It is gitignored and the server loads it automatically:

ROBLOX_OPEN_CLOUD_KEY=paste_the_key_here
ROBLOX_UNIVERSE_ID=000000
ROBLOX_PLACE_ID=000000
ROBLOX_CREATOR_USER_ID=000000   # only for upload_asset (your user id)

Or put the same variables in your MCP client's env block instead (those take precedence). Reconnect the MCP server after changing either. Each tool works when the key grants its scope and returns Roblox's own error if a scope is missing, so you can add scopes as you go.


Tools

Connection

<details><summary><code>studio_status</code></summary>Whether a Studio is connected, the active place, and any other connected studios.</details> <details><summary><code>ping_studio</code></summary>Round-trip a ping through the plugin to confirm the live bridge works.</details> <details><summary><code>list_studios</code></summary>List every connected (or recently seen) Studio: place, whether it is active, last-seen, and playtest state.</details> <details><summary><code>set_active_studio</code></summary>Choose which connected Studio the tools target (by id, id prefix, or place name). Automatic with one Studio.</details>

Read and inspect

<details><summary><code>get_file_tree</code></summary>List the instance tree from a path (default the whole game), bounded by depth.</details> <details><summary><code>get_instance_children</code></summary>List the direct children (name and class) of an instance.</details> <details><summary><code>get_instance_properties</code></summary>Read an instance's name, class, full path, attributes, and a curated set of common engine properties (Position, Size, Color, Material, Anchored, Text, and so on).</details> <details><summary><code>search_objects</code></summary>Find instances whose name contains a query, optionally filtered by exact class or by class-and-subclasses (isA).</details> <details><summary><code>search_by_property</code></summary>Find instances whose property equals a value, optionally filtered by exact class or by class-and-subclasses (isA).</details> <details><summary><code>get_script_source</code></summary>Read the source of a Script, LocalScript, or ModuleScript.</details> <details><summary><code>grep_scripts</code></summary>Search script sources for a substring; returns path, line number, and line.</details> <details><summary><code>get_output_log</code></summary>Recent Studio Output entries (message, type, timestamp).</details> <details><summary><code>get_selection</code></summary>The instances currently selected in Studio.</details> <details><summary><code>get_class_info</code></summary>Look up a Roblox class's members (properties, methods, events) with their types, inherited members folded in. Answered from a bundled API reflection dump, so it needs no Studio and no key.</details>

Spatial (read-only)

<details><summary><code>raycast</code></summary>Cast a ray and report the first hit (instance, position, normal, material, distance) or no hit, with an optional excluded subtree.</details> <details><summary><code>get_bounding_box</code></summary>The world-space bounding box (center and size) of a Model or BasePart.</details> <details><summary><code>find_spawns</code></summary>List the SpawnLocations under a path: position, whether each is enabled, and whether it is neutral.</details> <details><summary><code>capture_screenshot</code></summary>Capture the Studio viewport as a JPEG image so the agent can see the scene. Needs the plugin connected and Allow Mesh / Image APIs enabled (Game Settings, Security). Edit mode only.</details>

Edit (each is one undo step)

<details><summary><code>create_instance</code></summary>Create an instance of a class with an optional name and initial properties.</details> <details><summary><code>delete_instance</code></summary>Destroy an instance and its descendants.</details> <details><summary><code>set_property</code></summary>Set one typed property (primitive, Vector3, Color3, UDim2, CFrame, EnumItem, or an instance reference).</details> <details><summary><code>update_script_source</code></summary>Replace a script's source through the script editor (the supported write path).</details> <details><summary><code>insert_model</code></summary>Insert an asset by id, with optional reposition or unpack.</details> <details><summary><code>mass_create</code></summary>Create many instances in one undo step (atomic, or best-effort with per-item results).</details> <details><summary><code>ma

Truncated for display — read the full file on GitHub.

Related Skills

View on GitHub
GitHub Stars3
CategorySecurity
Updated1mo ago
Forks0

Languages

Rust

Trust signals

92/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 low