LUA001 Client value goes straight into money, items or jobs
possible Lua code
A server net event passes an argument from the client into AddMoney, AddItem or SetJob without any check.
Why it matters
Cheaters can trigger server events with any arguments they like. Without checks on the server they can give themselves money, items or jobs. This is a heuristic: it looks for an if statement that uses the value before the call, so read the code before changing it.
How to fix
Never trust the client. Validate type and range on the server, check distance and permissions, or compute the value server-side.
RegisterNetEvent('shop:sell', function(amount)
local player = exports.qbx_core:GetPlayer(source)
player.Functions.AddMoney('cash', amount)
end)RegisterNetEvent('shop:sell', function(count)
if type(count) ~= 'number' or count < 1 or count > 10 then return end
local player = exports.qbx_core:GetPlayer(source)
if not player then return end
player.Functions.AddMoney('cash', count * Config.Price) -- server-side price
end)Your framework uses other names? Add them to config.json: "lua": { "sensitiveFunctions": ["GiveCash"] }.
Not a problem in your case?
Add -- molfar-audit-ignore LUA001 on the reported line (or the line above it), or ignore it in config.json: "ignore": [{ "rule": "LUA001", "resource": "your_resource" }].