Tripwire
Agentic MCP for Roblox. Run tests and find exploits in your game from Claude Code, Codex, or Gemini.
Install / Use
claude mcp add aliboIly -- npx -y github:aliboIly/TripwireIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of Tripwire
Tripwire scores 80/100 on our quality scale, 642nd of 790 Security skills we index.
Its MCP Server is 23 KB long, well organised into 27 sections with 9 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated 35 days ago, so Tripwire is actively maintained.
- Our last check on 2026-09-18 found the source still online.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-09-29. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
Tripwire compared with similar skills
All 4 of these similar skills score higher than Tripwire; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| Tripwire (this skill)by aliboIly | 80 | 3 | 35d ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 86.0k | 13d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.0k | today | CLAUDE.md |
| rufloby ruvnet | 100 | 73.4k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
Frequently asked questions
- How do I install Tripwire?
- Run
claude mcp add aliboIly -- npx -y github:aliboIly/Tripwire. The install tabs above show the steps for each supported agent. - Which AI agents does Tripwire work with?
- It is written for Claude Code, Claude Desktop, Gemini CLI and OpenAI Codex, as a MCP Server file. Other agents that read the same format can often use it too.
- Is Tripwire safe to use?
- Our scan of the first 100 KB of the file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is Tripwire still maintained?
- The repository was last updated 35 days ago, so Tripwire is actively maintained.
Skill content
View source on GitHubTripwire
made by alibolly
An MCP server that gives an AI coding agent real control of Roblox Studio and Roblox Open Cloud, with a test-and-security layer no other Studio MCP has.
</div>Tripwire lets an assistant read, write, and edit the data model, drive playtests with simulated input, run tests-as-code headlessly in the real engine, flag client-trust exploits in game code, and call the Open Cloud APIs (DataStores, MessagingService, Memory Stores, and more). The Studio tools need no API key; the headless test, asset, and Open Cloud tools use an Open Cloud key.
Requirements
- An MCP client: Claude Code, Codex, Gemini, or any client that speaks MCP over stdio.
- Roblox Studio, for the Studio tools. These need no API key.
- Node.js, only if you run the server with
npx. The prebuilt binary needs no Node. - For the headless test, asset, and Open Cloud tools: a published place and a Roblox Open Cloud API key. See Open Cloud setup.
Quickstart
Tripwire is for Roblox developers who drive Studio through an AI coding agent.
- Wire the server into your MCP client (one command or a small config block, see Install below).
- Install the Studio plugin so the Studio tools can reach Studio (see the plugin step in Install).
- Open your place in Studio, turn on Game Settings > Security > Allow HTTP Requests, then click the Tripwire toolbar button and press Connect in the panel. The panel shows Connected and the Output prints
[Tripwire v...] connected. - Ask your agent to run
studio_status. A connected Studio confirms the bridge works. - Optional: add an Open Cloud key for the headless test, asset, and Open Cloud tools (see Open Cloud setup).
Install
Tripwire's server is a single binary. The easiest way to run it is with npx, which fetches the
prebuilt binary for your platform, so there is no Rust toolchain to install. Prefer a manual binary
or a source build? See the Alternatives at the end of this section.
One command:
claude mcp add --transport stdio tripwire -- npx -y tripwire-roblox
Or add it to a project .mcp.json (or ~/.claude.json):
{
"mcpServers": {
"tripwire": {
"type": "stdio",
"command": "npx",
"args": ["-y", "tripwire-roblox"]
}
}
}
</details>
<details>
<summary><b>Codex</b></summary>
Add to ~/.codex/config.toml:
[mcp_servers.tripwire]
command = "npx"
args = ["-y", "tripwire-roblox"]
Or: codex mcp add tripwire -- npx -y tripwire-roblox
Add to ~/.gemini/settings.json (or a project .gemini/settings.json):
{
"mcpServers": {
"tripwire": {
"command": "npx",
"args": ["-y", "tripwire-roblox"]
}
}
}
Or: gemini mcp add tripwire npx -y tripwire-roblox
Any client that speaks MCP over stdio can run it:
command: npx
args: ["-y", "tripwire-roblox"]
</details>
<details>
<summary><b>Alternatives: prebuilt binary, or build from source</b></summary>
Prebuilt binary (no Node). Download the archive for your platform from the
Releases page (for example
tripwire-server-vX.Y.Z-aarch64-apple-darwin.tar.gz), extract it, and point your client's
command at the extracted tripwire-server with empty args.
Build from source (needs Rust):
git clone https://github.com/aliboIly/Tripwire.git
cd Tripwire/server
cargo build --release # produces server/target/release/tripwire-server
Then point your client's command at that binary path.
The Studio tools reach Studio through a small plugin that long-polls the local server. Grab
Tripwire.rbxmx from the Releases page, or build it:
cd Tripwire/plugin
npm install
npx rbxtsc
rojo build --output Tripwire.rbxmx
cp Tripwire.rbxmx ~/Documents/Roblox/Plugins/ # macOS; Windows: %LOCALAPPDATA%\Roblox\Plugins
Restart Studio, enable Game Settings > Security > Allow HTTP Requests, then click the
Tripwire toolbar button and press Connect in the panel. The panel shows Connected and
the Output prints [Tripwire v...] connected.
The Studio tools need no key. The Open Cloud tools do. See Open Cloud setup below for the full walkthrough.
</details>Open Cloud setup
Most of Tripwire needs no credentials. These tools do, because they call Roblox Open Cloud:
run_luau, the headless tests (run_tests, run_test_file, list_tests), upload_asset,
publish_place, and the DataStore, Ordered DataStore, MessagingService, Memory Store, platform,
and engagement tools. They authenticate with a Roblox Open Cloud API key.
Use at your own risk. An Open Cloud key is a real credential with real power over your experience. Depending on the scopes you grant it, it can read and overwrite your live DataStores, publish new versions of your place, upload assets to your account, and message your servers. Treat it like a password: grant only the scopes you actually use, restrict it to your own IP, never commit it, and revoke it if it leaks. You are responsible for what you do with it. Tripwire is not affiliated with or endorsed by Roblox.
1. Create the key
- Go to create.roblox.com/dashboard/credentials and sign in.
- Click Create API Key and name it (for example
Tripwire). - Under Access Permissions, add only the API systems for the tools you want, and grant each the operation it needs, scoped to your experience:
- Luau Execution (write):
run_luauand the headless tests. - universe-places (write):
publish_place. - Assets (read + write):
upload_asset. - DataStores and Ordered DataStores: the data-store tools.
- Messaging Service (publish) and Memory Stores: those tools.
- User/Group/Inventory/Subscription/Notification: the platform and engagement tools.
- Luau Execution (write):
- Under Security, set Accepted IP Addresses to your machine's IP, or
0.0.0.0/0to allow any (simplest for local use). Set an expiration if you want. - Click Save & Generate Key and copy the key string. It is shown only once.
2. Find your universe and place IDs
In the Studio command bar (View, then Command Bar), run:
print("universe", game.GameId, "place", game.PlaceId)
GameId is your ROBLOX_UNIVERSE_ID; PlaceId is your ROBLOX_PLACE_ID. The place must be
published to Roblox for Open Cloud to act on it.
3. Give Tripwire the credentials
Create a .env at the repo root. It is gitignored and the server loads it automatically:
ROBLOX_OPEN_CLOUD_KEY=paste_the_key_here
ROBLOX_UNIVERSE_ID=000000
ROBLOX_PLACE_ID=000000
ROBLOX_CREATOR_USER_ID=000000 # only for upload_asset (your user id)
Or put the same variables in your MCP client's env block instead (those take precedence).
Reconnect the MCP server after changing either. Each tool works when the key grants its scope and
returns Roblox's own error if a scope is missing, so you can add scopes as you go.
Tools
Connection
<details><summary><code>studio_status</code></summary>Whether a Studio is connected, the active place, and any other connected studios.</details> <details><summary><code>ping_studio</code></summary>Round-trip a ping through the plugin to confirm the live bridge works.</details> <details><summary><code>list_studios</code></summary>List every connected (or recently seen) Studio: place, whether it is active, last-seen, and playtest state.</details> <details><summary><code>set_active_studio</code></summary>Choose which connected Studio the tools target (by id, id prefix, or place name). Automatic with one Studio.</details>Read and inspect
<details><summary><code>get_file_tree</code></summary>List the instance tree from a path (default the whole game), bounded by depth.</details> <details><summary><code>get_instance_children</code></summary>List the direct children (name and class) of an instance.</details> <details><summary><code>get_instance_properties</code></summary>Read an instance's name, class, full path, attributes, and a curated set of common engine properties (Position, Size, Color, Material, Anchored, Text, and so on).</details> <details><summary><code>search_objects</code></summary>Find instances whose name contains a query, optionally filtered by exact class or by class-and-subclasses (isA).</details> <details><summary><code>search_by_property</code></summary>Find instances whose property equals a value, optionally filtered by exact class or by class-and-subclasses (isA).</details> <details><summary><code>get_script_source</code></summary>Read the source of a Script, LocalScript, or ModuleScript.</details> <details><summary><code>grep_scripts</code></summary>Search script sources for a substring; returns path, line number, and line.</details> <details><summary><code>get_output_log</code></summary>Recent Studio Output entries (message, type, timestamp).</details> <details><summary><code>get_selection</code></summary>The instances currently selected in Studio.</details> <details><summary><code>get_class_info</code></summary>Look up a Roblox class's members (properties, methods, events) with their types, inherited members folded in. Answered from a bundled API reflection dump, so it needs no Studio and no key.</details>Spatial (read-only)
<details><summary><code>raycast</code></summary>Cast a ray and report the first hit (instance, position, normal, material, distance) or no hit, with an optional excluded subtree.</details> <details><summary><code>get_bounding_box</code></summary>The world-space bounding box (center and size) of a Model or BasePart.</details> <details><summary><code>find_spawns</code></summary>List the SpawnLocations under a path: position, whether each is enabled, and whether it is neutral.</details> <details><summary><code>capture_screenshot</code></summary>Capture the Studio viewport as a JPEG image so the agent can see the scene. Needs the plugin connected and Allow Mesh / Image APIs enabled (Game Settings, Security). Edit mode only.</details>Edit (each is one undo step)
<details><summary><code>create_instance</code></summary>Create an instance of a class with an optional name and initial properties.</details> <details><summary><code>delete_instance</code></summary>Destroy an instance and its descendants.</details> <details><summary><code>set_property</code></summary>Set one typed property (primitive, Vector3, Color3, UDim2, CFrame, EnumItem, or an instance reference).</details> <details><summary><code>update_script_source</code></summary>Replace a script's source through the script editor (the supported write path).</details> <details><summary><code>insert_model</code></summary>Insert an asset by id, with optional reposition or unpack.</details> <details><summary><code>mass_create</code></summary>Create many instances in one undo step (atomic, or best-effort with per-item results).</details> <details><summary><code>maTruncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
86.0kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ruflo
73.4k🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native Claude Code / Codex / Hermes and many more Integrated
CowAgent
47.2kOpen-source super AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
