Lua safety and limits¶
Enabled mods can change your world and inventories. They must not get access to your computer (files, programs, or system libraries).
Allowed¶
- Functions on your script such as
initialize,use, andhitBlock Worldhelpers (spawn, query tiles, explosions, time)Utilshelpers- The documented object helpers:
self.item,self.armor,self.player,self.creature, plus structure, plant, and projectile helpers requireof scripts under the game's Lua folders and your own mod
Blocked¶
Scripts cannot:
- Read or write files, start programs, or use debugging tools
- Reach into undocumented game internals
- Load extra Lua files from arbitrary folders
- Load extra system libraries
- Reach around the helpers into hidden game objects
Mod Prep Validate flags many of these as errors before you publish. The game also blocks them while the mod is running. There is no “trusted mod” override.
Your saves are still exposed¶
The sandbox stops a script from using your computer. It does not stop a script from spawning items, dealing damage, or destroying terrain — those commands exist so gameplay mods can work. Only enable mods you trust with your saves.