The check on hosted files
Every file hosted here is read by a program on arrival and compiled on the game box, and both results are published on the listing as a check report about that exact file. Every hosted file gets an automated check and a compile result on a named Rust build; both are public. Here is what it does and does not do.
Which files: only those uploaded by their own authors and those taken unmodified from open-licensed GitHub repositories. Plugins hosted on uMod are linked from this site, never copied, so they are not checked or compiled here.
What it checks now
- The file itself: only
.cs, or a.zipof source, JSON, text and images, or a Rust.mapfile on its own (a map has no code, so it is hashed and its header read, not scanned). Anything else is refused before it is stored. No DLLs, no executables, ever. - Outbound network use: HTTP clients, sockets, web sockets, Discord webhook addresses, every URL in the source.
- Process and native code: starting processes, shell commands, native imports.
- Dynamic code loading: assembly loading, code generation, unsafe blocks.
- Encoded data: Base64 decoding at runtime, long encoded literals.
- Files and server: writes and deletes, server config and RCON references.
- Identity: hardcoded Steam IDs, admin flag changes.
- Game control: Harmony patches, console commands, the server manager, server stops, repeating timers, config writes.
- The hooks the plugin registers, by name.
- The SHA-256 of the file, shown beside the download.
- A compile check on the game box against the live Rust and Carbon files, twice: with Carbon's compat shims and without them. The report names the Rust build and the date it ran, and shows the compiler's errors when it fails. When Rust updates, every hosted file is compiled again; the compile board shows the current results.
- A hot-path read: which hooks run very often and what each does inside, repeating timers under one second, and walks over every entity on the server.
Findings are listed with file and line so anyone can look at the exact code. The process, dynamic loading, unsafe, Base64 decoding, RCON and Harmony rules read the code only: comments and the text inside strings are blanked first, so a comment that says "unsafe" or a chat message that mentions RCON is not a finding. A hit in the hard categories (process, native, dynamic loading, unsafe) stops the file being served until a person has looked at it.
The rules
Every rule the program runs, straight from its source. "blocks": the file is not served until a person looks. "look": worth reading the line. "note": common in honest plugins; listed so you know it is there.
| Area | Flags | Level | Reads |
|---|---|---|---|
| Network | outbound network use | look | whole file |
| Network | URL in source | note | whole file |
| Network | Discord webhook address | look | whole file |
| Network | Oxide/Carbon web request | note | whole file |
| Processes and native code | starts a process | blocks | code only |
| Processes and native code | reads process information | note | code only |
| Processes and native code | native code import | blocks | code only |
| Dynamic code loading | dynamic code loading | blocks | code only |
| Dynamic code loading | emits code at runtime (Harmony transpilers do this; read the patch) | look | code only |
| Dynamic code loading | unsafe code | blocks | code only |
| Encoded data | Base64 decoding at runtime | note | code only |
| Encoded data | long Base64-looking string literal | note | code and strings |
| Files and server config | file system write or delete | note | whole file |
| Files and server config | file stream write | note | whole file |
| Files and server config | names a server config file or the RCON password | note | code and strings |
| Files and server config | refers to RCON in code | note | code only |
| Steam IDs and admin | hardcoded Steam ID | note | whole file |
| Steam IDs and admin | changes or checks admin status | note | whole file |
| Game control | Harmony patch | note | code only |
| Game control | runs console commands or stops the server | note | whole file |
| Game control | uses the server manager | note | whole file |
| Game control | repeating timer | note | whole file |
| Config writes | writes the config file | note | whole file |
What it does not do
It does not say "safe". It does not read the logic, judge whether the plugin is any good, open the config it ships with, or know whether an address it found is a friend's Discord or something else. A clean report means the program found nothing in the categories above, nothing more. A file that compiles has not been run on a live server by this check. Read the report, read the config, test on a throwaway server.
