No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger
0 material
1 low
What this review found
No material or immediate-danger item was identified.
Contextual expected matches (1)
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · high confidence
A scanner thought the code might be hiding something, but the actual code is plain and readable JavaScript. There is no hidden or disguised code.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code. The match applies to this repository.
Contextual assessment: JS-X-Ray flagged this as an obfuscated-code signal at line 1, but the supplied source context shows standard ES module imports and straightforward extension boilerplate. No minified, packed, eval-based, or encoded constructs are present. Scanner confidence was low and the signal is a false positive against normal readable code.
Impact: none · Exploitability: unlikely
Developer action: none
Scanner javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule javascript.xray.obfuscated-code
File role production
Source index.js:1
Coverage and limitations
Inventory 38 files · 389992 bytes
Contextual coverage 1 of 1 candidates assessed
JavaScript coverage
Status Complete
Candidates 1 files · 82359 bytes
X-Ray review families 1 warning occurrences compacted to 1 evidence-preserving review families
Representations 1 raw · 0 decoded · 0 normalized · 0 bundle modules
Stage scans 1 raw signatures · 1 raw AST · 1 raw OpenGrep · 0 derived signatures · 0 derived AST · 0 derived OpenGrep
Tools
Limitations
This advisory review cannot prove the absence of unknown behavior.
Technical scan identity
Full commit 9243b9c1ab54269f830d79b1aa0af3052be6ef54
Completed Aug 24, 2026
History depth 20 commits
Method Deterministic evidence with contextual review
Reviewer nano-gpt.com · zai-org/glm-latest
Scanner 0.1.0
Scanner policy 5
Rule catalog 2
Contextual policy 5
Ecosystem context sillytavern-community-v1
Prompt contextual-review-v7
Assessment schema contextual-assessment-v2
Review provenance 1 fresh / 0 reused groups · 1 fresh / 0 reused candidates
Review source reports none
Evidence triage 0 deterministic / 1 contextual candidates · 1 contextual / 1 total behavior cases
Model budget 1 model call · 1 / 12 fresh cases · 19360 / 200000 estimated input · 13097 / 250000 actual input · 482 / 40000 output tokens
Review batching 1 model call · up to 1 groups and 1 candidates per call · 0 retry calls · 0 over-budget singleton calls
Review usage 13097 input · 482 output · 0 cache read · 0 reasoning tokens
Report 2bc52c8f33c2e1a985d4457e19e07f0c60e28e2e82be0f76d8531ffed23a8f3f