Skip to content
intellect / softworks
Intellect Softworks
Sandboxed runtime reference

LuaVM Documentation

Build automations, read Intellect settings, inspect player snapshots, draw overlay primitives, create custom interfaces, and use the attached-engine bridge without exposing the host operating system.

No file access No process execution Guarded HTTPS Execution limits Engine instance API

Getting started

Open the Script page in Intellect and choose Lua VM. Enter Lua code in the upper editor and press Execute. Output, warnings, syntax errors, and runtime errors appear in the console beneath it.

Use Drawing Example or Game UI Example to load a known-good template.
Edit the template. Loading an example replaces the complete editor contents.
Press Execute. Scripts run on a worker thread under a guarded instruction and time budget.
Use Restart VM to clear runtime state, remove drawings, and restore a native Game page.
Hello LuaVM
print("Lua VM ready")

local enabled = intellect.get("Visuals.BoxESP")
print("Box ESP:", enabled)

Security model

The LuaVM is capability-based. A script only sees APIs Intellect explicitly provides. Standard operating-system and package-loading modules are removed, and CLR or WinForms objects are never handed to Lua code.

Host access blocked

Files, folders, registry, shell commands, processes, DLL loading, package loading, raw sockets, and arbitrary WinForms access.

Attached-engine access

Player snapshots, overlay drawing, input helpers, game services, instance creation, GC inspection, and explicit engine-memory helpers are available while attached.

The sandbox protects the host OS, not the attached game state.
Engine APIs can modify live state and are version-sensitive. Use them only in a test place you own. Allow Unsafe LuaVM unlocks permission-gated HTTPS GET reads but never restores io, os, require, process execution, or filesystem APIs.
750 msactive execution budget
1 MBmaximum HTTPS body
10 secHTTPS timeout

Unavailable globals

io, os, package, debug, require, dofile, and loadfile are unavailable. Calling them produces a normal Lua error rather than touching the computer.

Lua basics

The runtime uses Lua syntax through MoonSharp. Variables, tables, functions, loops, conditions, and standard soft-sandbox helpers work normally.

Functions and conditions
local function describe(value)
 if value thenreturn"enabled"endreturn"disabled"endprint(describe(intellect.get("Visuals.BoxESP")))
Long-running or infinite loops are interrupted by the execution guard. Keep callbacks small and avoid busy-wait loops.

Types and task helpers

The current runtime includes Roblox-style value constructors and compatibility helpers for scripts that need positions, screen points, transforms, interpolation, or scheduled callbacks.

APIDescription
Vector2.new(x, y)Creates a 2D value with X and Y components.
Vector3.new(x, y, z)Creates a 3D value used by instance and world helpers.
CFrame.new(...)Accepts coordinates, one Vector3 position, or position and look-at Vector3 values.
typeof(value)Returns names such as Vector2, Vector3, CFrame, or Instance.
math.clamp, math.lerp, math.roundAdditional numeric compatibility helpers.
table.find, table.clearTable search and reset helpers.
task.wait, task.spawn, task.delayWaits or schedules short callbacks. Global wait, spawn, and delay aliases are also available.
tick(), time()Returns Unix-style wall time or elapsed process time in seconds.
Values and scheduled work
local start = Vector3.new(0, 5, 0)
print(typeof(start), start.X, math.lerp(0, 10, 0.5))

task.delay(0.25, function()
 print("Delayed callback finished")
end)

Settings API

Settings use a two-part path in the form Group.Field. Field names are matched without case sensitivity. Only booleans, numbers, strings, and numeric arrays are exposed.

FunctionReturnsDescription
intellect.get(path)valueReads a supported setting.
intellect.set(path, value)trueWrites a compatible value and schedules a UI refresh.
intellect.toggle(path)booleanFlips a boolean setting and returns its new state.
Read and update settings
local current = intellect.get("Visuals.BoxESP")
print("Before:", current)

intellect.set("Visuals.BoxESP", true)
local nextValue = intellect.toggle("Visuals.BoxESP")
print("After toggle:", nextValue)
Use only settings visible in the current build. Unknown paths and incompatible value types are rejected with a descriptive console error.

Player snapshots

intellect.players() returns a new read-only-style snapshot table. Editing the returned Lua table does not modify Roblox or Intellect's player cache.

FieldTypeMeaning
namestringAccount username.
display_namestringCurrent display name.
user_idnumberRoblox user identifier.
healthnumberCached current health.
max_healthnumberCached maximum health.
armornumberDetected armor value.
toolstringDetected equipped tool name.
is_npcbooleanWhether the entry is considered an NPC.
List cached players
for index, player in ipairs(intellect.players()) doprint(index, player.display_name, player.health, player.tool)
end

Drawing API

Drawing.new(kind) creates a guarded 2D overlay primitive. Supported kinds are Square, Rectangle, Box, Line, Circle, and Text. Drawing.player_boxes() creates lightweight static-aspect boxes that automatically follow cached players without limb stretching.

MemberPurpose
Visible, FilledControls visibility and fill behavior.
X, Y, X2, Y2Start and end coordinates in overlay pixels.
Width, Height, RadiusPrimitive dimensions.
Rounding, Thickness, SegmentsShape quality and stroke appearance.
R, G, B, AColor channels from 0 to 1.
TextText primitive content.
SetPosition(x,y)Sets the start position.
SetSize(width,height)Sets rectangle dimensions.
SetEnd(x,y)Sets a line endpoint.
SetColor(r,g,b,a)Sets normalized RGBA color.
Remove()Marks this object for removal.
Static boxes that follow players
local boxes = Drawing.player_boxes()
boxes:SetColor(1, 1, 1, 0.9)
boxes.Thickness = 2
boxes.Rounding = 3
Player positions refresh at a capped rate while boxes render smoothly at overlay speed. The fixed aspect ratio prevents detached limbs or unusual animations from stretching the box.

Drawing.clear() and intellect.clear_drawings() remove every LuaVM drawing.

Frame drawing and input

The lowercase draw namespace renders immediate-mode primitives from a paint callback. Unlike persistent Drawing objects, these commands must run again each frame.

NamespaceAvailable members
callbackspaint(fn), onPaint(fn), tabpaint(name, fn), rescan(fn)
drawaddtext, calculatetextsize, screensize, addrect, addrectfilled, addgradient, addline, addcircle, addcirclefilled, addtriangle, addtrianglefilled, addquad, addquadfilled, WorldToScreen
inputKey state, key press/release, mouse buttons, cursor position, smooth mouse movement, wheel input, and mouse delta helpers.
Immediate overlay card
callbacks.paint(function()
 draw.addrectfilled(24, 24, 180, 46, 14, 14, 18, 235, 6)
 draw.addrect(24, 24, 180, 46, 169, 53, 53, 255, 6, 1)
 draw.addtext("LuaVM online", 40, 39, 245, 245, 248)
end)
Keep paint callbacks allocation-light. Persistent shapes belong in Drawing; rapidly changing HUD elements are a better fit for draw.

Game UI API

The declarative Game UI API creates Intellect-styled panels and controls without exposing WinForms. A script builds a page in memory, then requests activation with gameui.show().

FunctionDescription
gameui.begin(title)Starts a new page definition and sets the Game-tab title.
gameui.panel(title)Adds a panel and makes it the destination for following controls.
gameui.label(text)Adds informational text to the current panel.
gameui.checkbox(text, initial, callback)Adds a checkbox. The callback receives its new boolean state.
gameui.show()Requests page activation and returns whether it was accepted.
If a supported game page is loaded, Intellect displays an overwrite confirmation. Denying it leaves the native page untouched. Restart VM always restores the native page.
8panels per page
32controls per panel
Guardedcallback execution
Scripted Game page
gameui.begin("LuaVM Playground")
gameui.panel("Example Controls")
gameui.label("This panel belongs to a sandboxed script.")

gameui.checkbox("Print Test", false, function(enabled)
 print("Print Test checkbox:", enabled)
end)

if gameui.show() thenprint("Game page loaded")
end

Overlay UI API

overlayui builds a draggable Intellect-styled overlay window. It supports tabs, panels, labels, and callback-backed checkboxes. The lower-level imgui namespace is also available for custom tabs and controls.

APIMembers
overlayuibegin, tab, panel, label, checkbox, show, hide
imguicreatetab, checkbox, sliderfloat, sliderint, button, text, textcolored, combo, colorpicker, inputtext, child/window helpers, tree helpers, and tooltip helpers.
Small overlay window
overlayui.begin("LuaVM Tools")
overlayui.tab("Main")
overlayui.panel("Status")
overlayui.label("Runtime connected")
overlayui.checkbox("Example toggle", false, function(value)
 print("Toggle:", value)
end)
overlayui.show()

Instance and engine API

Instance.new(className, parent, properties) creates a supported engine instance under a required parent. The parent may be an Instance object such as workspace or a numeric engine address. A successful call returns the created numeric address; failure returns nil.

MemberDescription
Instance.new(class, parent, props)Creates an instance. Part properties currently include Position, Size, Color, Transparency, CanCollide, and Anchored.
SetPartPosition, SetPartSizeUpdates a created part using a Vector3 or numeric components.
SetPartTransparency, SetPartCanCollide, SetPartColorUpdates supported appearance and collision properties.
SetParent(address, parentAddress)Moves an engine instance to a new parent.
DestroyInstance(address)Destroys a created instance. Destroy is an alias.
game:GetService(name)Resolves a service. GetService(name), workspace, and Workspace aliases are available.
Harmless anchored test part
local part = Instance.new("Part", workspace, {
 Position = Vector3.new(0, 8, 0),
 Size = Vector3.new(2, 2, 2),
 Color = { 0.35, 0.75, 1.0 },
 Transparency = 0.35,
 CanCollide = false,
 Anchored = true
})

print("Created address:", part)
Instance and direct engine helpers require a valid attachment and current offsets. They are privileged, version-sensitive APIs; test them only in a place you control and always clean up created objects.

GC diagnostics

The GC namespace can inspect named runtime entries and report scanner diagnostics. Results are returned as Lua tables containing the fields discovered by the current build.

FunctionDescription
getgc(filter)Returns matching GC rows. The filter may be omitted.
setgc(name, field, value)Attempts to update a numeric GC value and returns a boolean result.
gc.getgcinfo()Returns current scanner information.
getsec(name)Returns the last diagnostic text for a named lookup.
Read-only GC search
local results = getgc("ExampleName")
print("Matches:", #results)

for _, entry in ipairs(results) doprint(entry.key, entry.value, entry.type, entry.addr)
end

HTTPS requests

Enable Allow Unsafe LuaVM to make http.get(url) available. Every request pauses and displays the complete destination in a centered Allow or Deny modal.

Allowed responses

HTTPS text, JSON, XML, and XHTML content up to 1 MB.

Rejected requests

HTTP, redirects, local/private destinations, executable or script paths, archives, installers, and binary content.

Approved JSON read
local body = http.get("https://example.com/data.json")
print("Received characters:", #body)
The response remains an in-memory Lua string. The HTTP API cannot save, install, launch, or automatically execute downloaded content.

Console and errors

Use print(...) for normal output and warn(...) for warning output. Intellect also reports decorated syntax errors, runtime errors, denied permissions, unsupported settings, callback failures, and execution-limit interruptions.

Diagnostic output
print("Starting test", 1)
warn("This appears using warning colors")
  • Clear console removes visible output without resetting runtime state.
  • Clear drawings removes overlay primitives only.
  • Restart VM resets globals, drawings, and the scripted Game page.
  • Back to Emulator returns to Intellect's feature-script editor.

Complete examples

Settings report

Read settings and players
print("Box ESP:", intellect.get("Visuals.BoxESP"))

local players = intellect.players()
print("Cached players:", #players)
for _, player in ipairs(players) doprint(player.display_name, player.health, player.max_health)
end

Game-page feature toggle

Connect a checkbox to a setting
gameui.begin("Visual Controls")
gameui.panel("ESP")

local initial = intellect.get("Visuals.BoxESP")
gameui.checkbox("Box ESP", initial, function(enabled)
 intellect.set("Visuals.BoxESP", enabled)
 print("Box ESP changed:", enabled)
end)

gameui.show()

Quick reference

NamespaceAvailable members
intellectget, set, toggle, players, clear_drawings
Value typesVector2.new, Vector3.new, CFrame.new, typeof
Drawingnew, player_boxes, clear
draw / callbacksImmediate shapes and frame, tab-paint, or rescan callbacks
inputKeyboard, mouse button, cursor, delta, smooth movement, and scroll helpers
gameuibegin, panel, label, checkbox, show
overlayuibegin, tab, panel, label, checkbox, show, hide
imguiTabs, buttons, text, checkboxes, sliders, combos, colors, text input, windows, trees, and tooltips
Instancenew, plus global part setters, SetParent, DestroyInstance, and Destroy
gameGetService, ReadMemory, WriteMemory; also workspace and Workspace
gcgetgc, setgc, getgcinfo, and global getsec
taskwait, spawn, delay, cancel
utilityplaysound, getdeviceid, isuntrusted, getwarnings, clearwarnings
httpget when Allow Unsafe LuaVM is enabled and the request is approved
Consoleprint, warn
Start from the built-in examples. They always match the APIs supported by the installed Intellect build.