Check report RUN Whitelist v1.0.0
What an automated read of this exact file found. It is a list of facts about the code, not a safety verdict. Read it, then read the config, then test on a throwaway server.
Compile check
Compiled on the live game box against Rust build 25670169 (game files dated 2026-10-02, Carbon files dated 2026-10-01), 2026-10-02 (6 days ago). "Without shims" means the plugin does not lean on Carbon's compatibility layer for APIs the game has removed, which is the version most likely to keep working after the next Rust update and to run on Oxide.
RUNWhitelist.cs
- With Carbon's shims: 1 error
- Without shims: 1 error
RUNWhitelist.cs(576,36): error CS1503: Argument 2: cannot convert from 'target-typed conditional expression' to 'string[]'
No hot-path hooks registered.
SHA-256 of this file
2176e571d07d0577bc32bc2f413a3b249a94ce05a5bc7c6fc7dff58a635e15c7
Hooks it registers 3
Findings 11
Network 4
| Level | What | Where | Line |
|---|---|---|---|
| note | URL in source | RUNWhitelist.cs:450 | var url = "https://api.steampowered.com/ISteamUser/GetFriendList/v1/" + |
| note | URL in source | RUNWhitelist.cs:687 | var url = "https://api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/" + |
| note | Oxide/Carbon web request | RUNWhitelist.cs:457 | webrequest.Enqueue(url, null, (code, body) => |
| note | Oxide/Carbon web request | RUNWhitelist.cs:692 | webrequest.Enqueue(url, null, (code, body) => |
Steam IDs and admin 2
| Level | What | Where | Line |
|---|---|---|---|
| note | changes or checks admin status | RUNWhitelist.cs:544 | if (!player.IsAdmin) |
| note | changes or checks admin status | RUNWhitelist.cs:558 | if (arg.Connection != null && !arg.IsAdmin) |
Game control 1
| Level | What | Where | Line |
|---|---|---|---|
| note | repeating timer | RUNWhitelist.cs:233 | _refreshTimer = timer.Every(_config.SteamApi.RefreshIntervalMinutes * 60f, () => RefreshAllFriends()); |
Config writes 4
| Level | What | Where | Line |
|---|---|---|---|
| note | writes the config file | RUNWhitelist.cs:137 | SaveConfig(); |
| note | writes the config file | RUNWhitelist.cs:152 | SaveConfig(); |
| note | writes the config file | RUNWhitelist.cs:831 | SaveConfig(); |
| note | writes the config file | RUNWhitelist.cs:865 | SaveConfig(); |
"blocks": the file is not served until a person looks. "look": worth reading the line. "note": common in honest plugins (a URL, a config write); listed so you know it is there.
What was checked
Outbound network use and URLs, Discord webhooks, process and shell use, native imports, dynamic assembly loading and code generation, unsafe blocks, Base64 decoding and long encoded literals, file writes and deletes, server config and RCON references, hardcoded Steam IDs, admin flag changes, Harmony patches, console commands and server stops, repeating timers, config writes, and the hook names registered. The compile check above builds the file on the live game box against the current Rust and Carbon files, publicized the way Carbon does at boot, with Carbon's compat shims and without them. Not checked: whether the logic is correct or kind, or whether the config it ships with points anywhere.
