Getting started
Open the Script page in Intellect and choose Lua VM. Enter Lua code in the upper editor and press Execute. Output, warnings, syntax errors, and runtime errors appear in the console beneath it.
print("Lua VM ready") local enabled = intellect.get("Visuals.BoxESP") print("Box ESP:", enabled)
Security model
The LuaVM is capability-based. A script only sees APIs Intellect explicitly provides. Standard operating-system and package-loading modules are removed, and CLR or WinForms objects are never handed to Lua code.
Files, folders, registry, shell commands, processes, DLL loading, package loading, raw sockets, and arbitrary WinForms access.
Player snapshots, overlay drawing, input helpers, game services, instance creation, GC inspection, and explicit engine-memory helpers are available while attached.
Engine APIs can modify live state and are version-sensitive. Use them only in a test place you own. Allow Unsafe LuaVM unlocks permission-gated HTTPS GET reads but never restores
io, os, require, process execution, or filesystem APIs.Unavailable globals
io, os, package, debug, require, dofile, and loadfile are unavailable. Calling them produces a normal Lua error rather than touching the computer.
Lua basics
The runtime uses Lua syntax through MoonSharp. Variables, tables, functions, loops, conditions, and standard soft-sandbox helpers work normally.
local function describe(value) if value thenreturn"enabled"endreturn"disabled"endprint(describe(intellect.get("Visuals.BoxESP")))
Types and task helpers
The current runtime includes Roblox-style value constructors and compatibility helpers for scripts that need positions, screen points, transforms, interpolation, or scheduled callbacks.
| API | Description |
|---|---|
Vector2.new(x, y) | Creates a 2D value with X and Y components. |
Vector3.new(x, y, z) | Creates a 3D value used by instance and world helpers. |
CFrame.new(...) | Accepts coordinates, one Vector3 position, or position and look-at Vector3 values. |
typeof(value) | Returns names such as Vector2, Vector3, CFrame, or Instance. |
math.clamp, math.lerp, math.round | Additional numeric compatibility helpers. |
table.find, table.clear | Table search and reset helpers. |
task.wait, task.spawn, task.delay | Waits or schedules short callbacks. Global wait, spawn, and delay aliases are also available. |
tick(), time() | Returns Unix-style wall time or elapsed process time in seconds. |
local start = Vector3.new(0, 5, 0) print(typeof(start), start.X, math.lerp(0, 10, 0.5)) task.delay(0.25, function() print("Delayed callback finished") end)
Settings API
Settings use a two-part path in the form Group.Field. Field names are matched without case sensitivity. Only booleans, numbers, strings, and numeric arrays are exposed.
| Function | Returns | Description |
|---|---|---|
intellect.get(path) | value | Reads a supported setting. |
intellect.set(path, value) | true | Writes a compatible value and schedules a UI refresh. |
intellect.toggle(path) | boolean | Flips a boolean setting and returns its new state. |
local current = intellect.get("Visuals.BoxESP") print("Before:", current) intellect.set("Visuals.BoxESP", true) local nextValue = intellect.toggle("Visuals.BoxESP") print("After toggle:", nextValue)
Player snapshots
intellect.players() returns a new read-only-style snapshot table. Editing the returned Lua table does not modify Roblox or Intellect's player cache.
| Field | Type | Meaning |
|---|---|---|
name | string | Account username. |
display_name | string | Current display name. |
user_id | number | Roblox user identifier. |
health | number | Cached current health. |
max_health | number | Cached maximum health. |
armor | number | Detected armor value. |
tool | string | Detected equipped tool name. |
is_npc | boolean | Whether the entry is considered an NPC. |
for index, player in ipairs(intellect.players()) doprint(index, player.display_name, player.health, player.tool) end
Drawing API
Drawing.new(kind) creates a guarded 2D overlay primitive. Supported kinds are Square, Rectangle, Box, Line, Circle, and Text. Drawing.player_boxes() creates lightweight static-aspect boxes that automatically follow cached players without limb stretching.
| Member | Purpose |
|---|---|
Visible, Filled | Controls visibility and fill behavior. |
X, Y, X2, Y2 | Start and end coordinates in overlay pixels. |
Width, Height, Radius | Primitive dimensions. |
Rounding, Thickness, Segments | Shape quality and stroke appearance. |
R, G, B, A | Color channels from 0 to 1. |
Text | Text primitive content. |
SetPosition(x,y) | Sets the start position. |
SetSize(width,height) | Sets rectangle dimensions. |
SetEnd(x,y) | Sets a line endpoint. |
SetColor(r,g,b,a) | Sets normalized RGBA color. |
Remove() | Marks this object for removal. |
local boxes = Drawing.player_boxes() boxes:SetColor(1, 1, 1, 0.9) boxes.Thickness = 2 boxes.Rounding = 3
Drawing.clear() and intellect.clear_drawings() remove every LuaVM drawing.
Frame drawing and input
The lowercase draw namespace renders immediate-mode primitives from a paint callback. Unlike persistent Drawing objects, these commands must run again each frame.
| Namespace | Available members |
|---|---|
callbacks | paint(fn), onPaint(fn), tabpaint(name, fn), rescan(fn) |
draw | addtext, calculatetextsize, screensize, addrect, addrectfilled, addgradient, addline, addcircle, addcirclefilled, addtriangle, addtrianglefilled, addquad, addquadfilled, WorldToScreen |
input | Key state, key press/release, mouse buttons, cursor position, smooth mouse movement, wheel input, and mouse delta helpers. |
callbacks.paint(function() draw.addrectfilled(24, 24, 180, 46, 14, 14, 18, 235, 6) draw.addrect(24, 24, 180, 46, 169, 53, 53, 255, 6, 1) draw.addtext("LuaVM online", 40, 39, 245, 245, 248) end)
Drawing; rapidly changing HUD elements are a better fit for draw.Game UI API
The declarative Game UI API creates Intellect-styled panels and controls without exposing WinForms. A script builds a page in memory, then requests activation with gameui.show().
| Function | Description |
|---|---|
gameui.begin(title) | Starts a new page definition and sets the Game-tab title. |
gameui.panel(title) | Adds a panel and makes it the destination for following controls. |
gameui.label(text) | Adds informational text to the current panel. |
gameui.checkbox(text, initial, callback) | Adds a checkbox. The callback receives its new boolean state. |
gameui.show() | Requests page activation and returns whether it was accepted. |
gameui.begin("LuaVM Playground") gameui.panel("Example Controls") gameui.label("This panel belongs to a sandboxed script.") gameui.checkbox("Print Test", false, function(enabled) print("Print Test checkbox:", enabled) end) if gameui.show() thenprint("Game page loaded") end
Overlay UI API
overlayui builds a draggable Intellect-styled overlay window. It supports tabs, panels, labels, and callback-backed checkboxes. The lower-level imgui namespace is also available for custom tabs and controls.
| API | Members |
|---|---|
overlayui | begin, tab, panel, label, checkbox, show, hide |
imgui | createtab, checkbox, sliderfloat, sliderint, button, text, textcolored, combo, colorpicker, inputtext, child/window helpers, tree helpers, and tooltip helpers. |
overlayui.begin("LuaVM Tools") overlayui.tab("Main") overlayui.panel("Status") overlayui.label("Runtime connected") overlayui.checkbox("Example toggle", false, function(value) print("Toggle:", value) end) overlayui.show()
Instance and engine API
Instance.new(className, parent, properties) creates a supported engine instance under a required parent. The parent may be an Instance object such as workspace or a numeric engine address. A successful call returns the created numeric address; failure returns nil.
| Member | Description |
|---|---|
Instance.new(class, parent, props) | Creates an instance. Part properties currently include Position, Size, Color, Transparency, CanCollide, and Anchored. |
SetPartPosition, SetPartSize | Updates a created part using a Vector3 or numeric components. |
SetPartTransparency, SetPartCanCollide, SetPartColor | Updates supported appearance and collision properties. |
SetParent(address, parentAddress) | Moves an engine instance to a new parent. |
DestroyInstance(address) | Destroys a created instance. Destroy is an alias. |
game:GetService(name) | Resolves a service. GetService(name), workspace, and Workspace aliases are available. |
local part = Instance.new("Part", workspace, { Position = Vector3.new(0, 8, 0), Size = Vector3.new(2, 2, 2), Color = { 0.35, 0.75, 1.0 }, Transparency = 0.35, CanCollide = false, Anchored = true }) print("Created address:", part)
GC diagnostics
The GC namespace can inspect named runtime entries and report scanner diagnostics. Results are returned as Lua tables containing the fields discovered by the current build.
| Function | Description |
|---|---|
getgc(filter) | Returns matching GC rows. The filter may be omitted. |
setgc(name, field, value) | Attempts to update a numeric GC value and returns a boolean result. |
gc.getgcinfo() | Returns current scanner information. |
getsec(name) | Returns the last diagnostic text for a named lookup. |
local results = getgc("ExampleName") print("Matches:", #results) for _, entry in ipairs(results) doprint(entry.key, entry.value, entry.type, entry.addr) end
HTTPS requests
Enable Allow Unsafe LuaVM to make http.get(url) available. Every request pauses and displays the complete destination in a centered Allow or Deny modal.
HTTPS text, JSON, XML, and XHTML content up to 1 MB.
HTTP, redirects, local/private destinations, executable or script paths, archives, installers, and binary content.
local body = http.get("https://example.com/data.json") print("Received characters:", #body)
Console and errors
Use print(...) for normal output and warn(...) for warning output. Intellect also reports decorated syntax errors, runtime errors, denied permissions, unsupported settings, callback failures, and execution-limit interruptions.
print("Starting test", 1) warn("This appears using warning colors")
- Clear console removes visible output without resetting runtime state.
- Clear drawings removes overlay primitives only.
- Restart VM resets globals, drawings, and the scripted Game page.
- Back to Emulator returns to Intellect's feature-script editor.
Complete examples
Settings report
print("Box ESP:", intellect.get("Visuals.BoxESP")) local players = intellect.players() print("Cached players:", #players) for _, player in ipairs(players) doprint(player.display_name, player.health, player.max_health) end
Game-page feature toggle
gameui.begin("Visual Controls") gameui.panel("ESP") local initial = intellect.get("Visuals.BoxESP") gameui.checkbox("Box ESP", initial, function(enabled) intellect.set("Visuals.BoxESP", enabled) print("Box ESP changed:", enabled) end) gameui.show()
Quick reference
| Namespace | Available members |
|---|---|
intellect | get, set, toggle, players, clear_drawings |
| Value types | Vector2.new, Vector3.new, CFrame.new, typeof |
Drawing | new, player_boxes, clear |
draw / callbacks | Immediate shapes and frame, tab-paint, or rescan callbacks |
input | Keyboard, mouse button, cursor, delta, smooth movement, and scroll helpers |
gameui | begin, panel, label, checkbox, show |
overlayui | begin, tab, panel, label, checkbox, show, hide |
imgui | Tabs, buttons, text, checkboxes, sliders, combos, colors, text input, windows, trees, and tooltips |
Instance | new, plus global part setters, SetParent, DestroyInstance, and Destroy |
game | GetService, ReadMemory, WriteMemory; also workspace and Workspace |
gc | getgc, setgc, getgcinfo, and global getsec |
task | wait, spawn, delay, cancel |
utility | playsound, getdeviceid, isuntrusted, getwarnings, clearwarnings |
http | get when Allow Unsafe LuaVM is enabled and the request is approved |
| Console | print, warn |
