Download and account safety

Is Verity Mod Safe? Source and Virus Checks

A project page from the author is a safer starting point than a repost, but no title, platform, scan, or popular video can guarantee that every file and setup is risk-free.

Information checked 2026-08-25 Dates and versions can change.

The honest answer

There is no useful yes-or-no safety label for every file called “Verity Mod.” The name is used in searches for an original horror character, maintained Java and Bedrock adaptations, older projects, same-name uploads, and reposts. Safety must be evaluated for a specific source, Project ID, release, and configuration.

This guide identifies three project pages: Verity JE by VarmiteYT, Verity BE by Utlover65, and Verity - Bedrock Edition by PnTMC. They are useful starting points, not security certificates. You can inspect their authors, file histories, versions, changelogs, and support information instead of downloading an isolated package from an unknown host.

Five checks before downloading

  1. Project details: verify the title, author, Project ID, edition, and supported version. Verity JE is ID 1591438. The Bedrock projects are Verity BE ID 1574632 and Verity - Bedrock Edition ID 1575941.
  2. Link path: arrive at the project page through a normal HTTPS URL. Avoid URL shorteners, ad-gated redirects, shared drives, chat attachments, and “backup” links.
  3. Version fit: choose the exact game version and loader or Bedrock build. A file that cannot belong in your environment is already the wrong file, even before a security scan.
  4. Local scan: use current operating-system and security tools. A clean scan lowers concern but does not prove harmless behavior; a positive detection needs investigation rather than automatic dismissal.
  5. Controlled test: use a separate launcher profile or test world, back up important saves, and add no unrelated mods during the first run.

Keep the project page open while testing. If the package name, size, date, or dependency expectations differ from the page you intended to use, stop and re-check the download history.

Project source versus “official”

“Official” can mean several things and is often used too broadly. ThatMob is the creator source associated with the Verity character and video context. The playable Java and Bedrock projects are adaptations maintained by other people. The Verity JE page states that it has explicit permission from ThatMob, while both checked Bedrock team pages list thatmobyt as an Author member. Those project-specific signals do not transfer to every fork, reupload, or old package using the name.

The clearest description is the project page published by that adaptation’s author. It tells you who owns that release and where updates are published without pretending that Java, Bedrock, and the original videos are the same thing.

Same names and reused project slugs

Search results contain several projects that should not be merged. The CurseForge address /minecraft/mc-mods/verity-mod currently opens Verity Remake by Verity_remake_creator, Project ID 1587777. It is not the Verity JE page, whose ID is 1591438. A familiar page address is not proof that the project stayed the same; verify the numeric ID shown on the page.

Modrinth also lists a Verity Java project for Fabric 1.20.1 and a separate Verity (Horror) project for Forge 1.20.1. Their own pages support only their own files and claims; they do not show that either project is a mirror or successor of Verity JE. Likewise, Verity Pocket Edition (Be) by vexi1111_, Project ID 1596246, is separate from the two Bedrock projects described here.

This does not label those additional projects malicious. It only establishes that they are different projects. Evaluate each source, author, Project ID, loader, game version, permissions, and history independently.

Mirrors and recovered removed files

A mirror removes context. You may lose the project ID, changelog, dependency relation, moderation history, and a way to tell whether a newer file replaced an older one. A recovered file adds another uncertainty: even if the person sharing it has a genuine old package, you cannot establish that the copy is unchanged merely from its title.

Do not use a mirror because the current project does not support your preferred version. An unknown download cannot safely fill that compatibility gap. Choose a supported version, wait for a project update, or do not install.

When a project is removed, avoid assigning a reason unless the project author or platform identifies that specific project. Community threads about Verity contain conflicting stories, including security claims and creator disputes. They show that people are asking, not that one explanation is true.

Protect your Groq API key

The Java project can use Groq. A Groq API key authorizes requests under your account and should be treated like a password. Create it only in the Groq console. Enter it only in the current Verity configuration location documented by the project. This site has no field for it and no reason to receive it.

Do not paste the value into:

  • a download website;
  • Discord, Reddit, YouTube comments, or direct messages;
  • a public support ticket;
  • a screenshot or livestream;
  • an unredacted log;
  • a public repository or shared configuration archive.

If exposure is possible, revoke the API key first. Deleting a message later does not guarantee that the value was not copied. Create a replacement and update the local configuration. When requesting help, describe the error code and redact the key completely; showing its first or last characters is rarely necessary.

Understand permissions and network behavior

An AI companion can legitimately use features that deserve attention: outbound network requests, microphone access for speech, local files for configuration, and a local Ollama service. You should still understand what data leaves your computer and which permissions are active.

For Groq, prompts leave the game to reach a cloud provider. For Ollama, model inference can remain on the local machine, but the service still listens on a local address and consumes system resources. For Bedrock, the add-on uses its project’s documented connection process. Review the current project description and avoid sending private information in prompts with any setup.

Horror-themed dialogue may imply that Verity knows more than it does. Treat narrative text as narrative unless you have reproducible technical evidence of unexpected access. Conversely, do not dismiss a real security alert merely because the mod is designed to be unsettling. Capture evidence, isolate the profile, and investigate the specific behavior.

Scan results need context

Security tools can produce false positives, especially for uncommon archives or software that makes network requests. They can also miss new threats. Do not rely on one badge, one commenter, or one scan result. Compare multiple signals: trusted source, expected file type, digital or platform metadata where available, current scan results, runtime network behavior, and community reports that include reproducible evidence.

If a scanner flags a package, do not disable protection just to make the warning disappear. Stop, confirm that the file came from the intended project, check whether the author addresses the exact detection, and submit it to your security vendor if appropriate. An author response is useful context but not a substitute for independent analysis.

Safe testing routine

Back up the world, use a dedicated profile, and close unrelated sensitive applications. Start with only the required loader, Verity, and listed dependencies. Observe whether the game opens expected network connections and whether microphone access occurs only when you use the speech feature. Keep the first prompts free of personal information.

After a successful test, add other mods gradually. Save the working version combination so future troubleshooting does not depend on memory. When updating, repeat the clean test before opening an important world.

How to judge safety claims

Project pages support author details, versions, stated features, and setup notes. Official documentation explains how Groq, Ollama, and Minecraft behave. Creator channels provide context for the original work. Reddit, Discord, and comments can reveal common confusion or symptoms, but allegations remain community reports or unconfirmed until stronger evidence appears.

That distinction matters for safety. Overconfident reassurance can lead users into risky downloads; overconfident accusations can harm people and still fail to identify a dangerous file. Exact project details and honest uncertainty are more useful than either extreme.

Quick answers

Frequently asked questions

Is the Verity Mod a virus?

This guide found no basis to label every project named Verity a virus, and it does not certify every file as safe. Verify the specific project, scan the file, review behavior, and avoid untraceable mirrors.

Does CurseForge make a Verity file completely safe?

A current CurseForge project provides author details and file history that a mirror lacks, but a hosting platform is not an absolute guarantee. Keep local security tools current and use a separate profile and world.

Is the Java adaptation authorized by ThatMob?

The Verity JE project page states that the adaptation has explicit permission from ThatMob. That statement supports this project's claimed relationship; it does not make every same-name upload authorized.

What should I do if my Groq API key leaked?

Revoke the exposed API key in the Groq console, create a replacement, update only the trusted local configuration, and remove it from posts, screenshots, logs, or repositories where possible.

References

Where this information comes from

Project page

Verity JE on CurseForge

Java project details, Project ID 1591438, stable Forge 1.20.1 main file 5.7.4, 6.0.0-beta.9 listing, legacy NeoForge branch, AI options, gallery, and author notices.

Checked

Project page

Verity BE on CurseForge

Bedrock project details, current author Utlover65, Project ID 1574632, current 4.1.2 file for 26.40, conflicting 26.30 setup copy, chat instructions, troubleshooting notes, and gallery.

Checked

Project page

Verity - Bedrock Edition on CurseForge

PnTMC Bedrock project details, Project ID 1575941, release 4.0.0 for Bedrock 26.40, Beta APIs, linked local setup guide, chat behavior, and team credits.

Checked

Project page

Verity Java on Modrinth

A separate same-name Java project for Minecraft 1.20.1 using Fabric, not the Forge/NeoForge Verity JE project.

Checked

Project page

Verity (Horror) on Modrinth

A separate Forge 1.20.1 project with its own author, features, and files; it does not confirm features in Verity JE.

Checked

Creator

ThatMob YouTube channel

Original creator context for the Verity character and video series.

Checked