MixMods Creator Directory

How to check a mod before you run it

Nobody here reads the code of a listing, so these are the checks a careful server owner does. None is required and none is a guarantee. Do the first two and you have caught most of what goes wrong.

1. Read the config it ships with

Most harm from a sold plugin is not clever: a Discord webhook, an admin Steam ID, an RCON line or a download URL sitting in the default config. Open the .json before you install and ask why each address or ID is there.

2. Have an AI read the source, then a second one

Paste the prompt below into ChatGPT, Gemini, Claude or Grok, then paste the whole .cs file after it. Run the same thing in a second, different AI and compare. Antivirus says "clean" for a plugin whose only payload is logic; two cold readers usually do not.

You are reviewing an Oxide/Carbon Rust game server plugin (C#). I did NOT write this. Treat it as untrusted. It may be AI-generated; look for invented APIs and dead calls too.

Flag anything that looks like malware, a backdoor, or abuse, with line references.

Check for:
1. Outbound HTTP/HTTPS/WebSocket calls (WebClient, HttpClient, UnityWebRequest, WebRequest, sockets): list every URL or host.
2. Discord webhooks, Telegram bots, pastebins, unknown IPs.
3. Process.Start, shell commands, downloading or executing files.
4. Reading Steam IDs, passwords, RCON, server.cfg or oxide/carbon data and sending them anywhere.
5. Hidden admin backdoors, silent ban evasion, godmode for specific Steam IDs.
6. Obfuscation, strings decoded at runtime, Base64 payloads.
7. File writes or deletes outside the plugin's own config and data paths.
8. Harmony patches that touch anti-cheat or other plugins.
9. Hardcoded Steam IDs with special privileges.
10. Anything that keeps running after the plugin is unloaded.
11. Calls to hooks, APIs or methods that do not exist in Oxide, Carbon or uMod, or look invented.

Reply with: RISK (Low / Medium / High / Critical); FINDINGS as a list; OK TO TRY? (Yes / Only on a test server / No); NOTES on what a normal plugin might still legitimately do (a Discord webhook for admin alerts can be fine).

Here is the full plugin source:

3. Match the file hash

If the listing shows a SHA-256, check the file you were sent: Get-FileHash .\file -Algorithm SHA256 on Windows, sha256sum file on Linux or Mac. A match means it is the file the creator listed, nothing more. A mismatch means ask the creator before you install.

4. Test server first

Load it on a throwaway server, watch the console for errors, and watch outbound connections for a few minutes. Then decide.

5. Extra tools, if you want them

VirusTotal for zips and DLLs (weak on plain source). Semgrep for dangerous C# patterns, run locally. Gitleaks for tokens and webhooks in the files. All third-party, none affiliated with us.

6. The check report on hosted files

Files are hosted here only when their author uploads them or they come from an open-licensed GitHub repository. Plugins hosted on uMod are linked, never copied, so there is no report here for them: check the file you download from uMod with steps 1 to 4. Any file hosted here gets an automated read on arrival: outbound network use, process and native code, dynamic loading, encoded data, file writes, server config and RCON references, hardcoded Steam IDs, Harmony patches, the hooks it registers. The report sits on the listing next to the download, about that exact file. What it checks and what it cannot. Every hosted file gets an automated check and a compile result on a named Rust build; both are public.