Exploiting is obviously against the Terms of Service, even when you are testing out your anti-cheat. Since you are the developer of the game however, you already have the ability to insert any code into your client/game at will through Studio. And through a ModuleScript you can load on the Client, you could even execute code at-will.
If you get slightly creative with the existing tools, everything you’d need to simulate what ‘exploiters’ do can already be done.