We could store an online database of signatures that are associated with the specific addon content. We could ask the website to give us a key that we could use to verify the addon's certificate. It really isn't that hard actually since the addon can't overwrite TCP objects
That sounds like an interesting idea, and I'm sure it could be pulled off. Might need some fine-tuning, but for the most part it sounds fool-proof.
It's a good idea but at this point in time it's not needed. There aren't very many malicious mods out there and they can always just be CRC banned.
You are correct, luckily we haven't run into many harmful mods so far. I do believe that the finished add-ons section is a bit unorganized however. We don't have the organized groups for add-ons like RTB had, (eg: weapons, bricks, etc). Now obviously this is simply one feature, but it could be expanded on. Maybe if the demand for organized add-ons goes up, this could be made.