Skip to content

Lua safety and limits

Enabled mods can change your world and inventories. They must not get access to your computer (files, programs, or system libraries).

Allowed

  • Functions on your script such as initialize, use, and hitBlock
  • World helpers (spawn, query tiles, explosions, time)
  • Utils helpers
  • The documented object helpers: self.item, self.armor, self.player, self.creature, plus structure, plant, and projectile helpers
  • require of scripts under the game's Lua folders and your own mod

Blocked

Scripts cannot:

  • Read or write files, start programs, or use debugging tools
  • Reach into undocumented game internals
  • Load extra Lua files from arbitrary folders
  • Load extra system libraries
  • Reach around the helpers into hidden game objects

Mod Prep Validate flags many of these as errors before you publish. The game also blocks them while the mod is running. There is no “trusted mod” override.

Your saves are still exposed

The sandbox stops a script from using your computer. It does not stop a script from spawning items, dealing damage, or destroying terrain — those commands exist so gameplay mods can work. Only enable mods you trust with your saves.