MixMods Creator Directory

The check on hosted files

Every file hosted here is read by a program on arrival and compiled on the game box, and both results are published on the listing as a check report about that exact file. Every hosted file gets an automated check and a compile result on a named Rust build; both are public. Here is what it does and does not do.

Which files: only those uploaded by their own authors and those taken unmodified from open-licensed GitHub repositories. Plugins hosted on uMod are linked from this site, never copied, so they are not checked or compiled here.

What it checks now

Findings are listed with file and line so anyone can look at the exact code. The process, dynamic loading, unsafe, Base64 decoding, RCON and Harmony rules read the code only: comments and the text inside strings are blanked first, so a comment that says "unsafe" or a chat message that mentions RCON is not a finding. A hit in the hard categories (process, native, dynamic loading, unsafe) stops the file being served until a person has looked at it.

The rules

Every rule the program runs, straight from its source. "blocks": the file is not served until a person looks. "look": worth reading the line. "note": common in honest plugins; listed so you know it is there.

AreaFlagsLevelReads
Networkoutbound network uselookwhole file
NetworkURL in sourcenotewhole file
NetworkDiscord webhook addresslookwhole file
NetworkOxide/Carbon web requestnotewhole file
Processes and native codestarts a processcode only
Processes and native codereads process informationnotecode only
Processes and native codenative code importcode only
Dynamic code loadingdynamic code loadingcode only
Dynamic code loadingemits code at runtime (Harmony transpilers do this; read the patch)lookcode only
Dynamic code loadingunsafe codecode only
Encoded dataBase64 decoding at runtimenotecode only
Encoded datalong Base64-looking string literalnotecode and strings
Files and server configfile system write or deletenotewhole file
Files and server configfile stream writenotewhole file
Files and server confignames a server config file or the RCON passwordnotecode and strings
Files and server configrefers to RCON in codenotecode only
Steam IDs and adminhardcoded Steam IDnotewhole file
Steam IDs and adminchanges or checks admin statusnotewhole file
Game controlHarmony patchnotecode only
Game controlruns console commands or stops the servernotewhole file
Game controluses the server managernotewhole file
Game controlrepeating timernotewhole file
Config writeswrites the config filenotewhole file

What it does not do

It does not say "safe". It does not read the logic, judge whether the plugin is any good, open the config it ships with, or know whether an address it found is a friend's Discord or something else. A clean report means the program found nothing in the categories above, nothing more. A file that compiles has not been run on a live server by this check. Read the report, read the config, test on a throwaway server.

← Back to the checking guide