TavernKeeper Scan Report

bmen25124/SillyTavern-Flowchart

Commit b7c091b Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 62 low

What this review found

No material or immediate-danger item was identified.

Deterministic technical evidence (52)
  • Dependency advisory GHSA-qx2v-qp2m-jg93:pkg:d0433ccd51b55fc561da06bf applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-gh4j-gqv2-49f6:pkg:2e769c3d435a393f7d6a63cc applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8gc5-j5rx-235r:pkg:1ba011ced44a3aa03556255b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-m7jm-9gc2-mpf2:pkg:eb295685e4f99fcf0f9aa306 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-h67p-54hq-rp68:pkg:032a72735b89e8109ae31a3d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-9cx6-37pm-9jff:pkg:ca52f57e7f6518348696e910 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fj3w-jwp8-x2g3:pkg:553721236f32a20b1e0db5b7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: webpack.config.cjs:7

  • Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:2f8d75dd087c1050a99a8192 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4c8g-83qw-93j6:pkg:181d5c1a6aff27dd93f86cff applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:a6af0e9fdfc814bb2702c837 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-23c5-xmqv-rm74:pkg:28c6f8e6010383b649a97a01 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v39h-62p7-jpjc:pkg:a6be302000b0d22d393bcd4e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-442j-39wm-28r2:pkg:c54738cea96a333e19b8bd79 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-xhpv-hc6g-r9c6:pkg:4114756074b3c1883ca427a6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:f943bf04aa1d0078992a0950 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-w5hq-g745-h8pq:pkg:dc7b41cc886ce4ad03b2d732 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3ppc-4f35-3m26:pkg:173c1b2fab8e025126fb982c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:309438d8c981844c76003c01 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-xjpj-3mr7-gcpf:pkg:2c93c7ce30edf86304d17bbe applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-jp2q-39xq-3w4g:pkg:720a7f211d1f6e8a46d0f289 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-jmr7-xgp7-cmfj:pkg:0a170fd273ac9e64ed7e2bb5 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7r86-cg39-jmmj:pkg:fa706fb036ae029fca4e7e55 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:56fd66430fa2724b4206a4ad applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-xvcm-6775-5m9r:pkg:41b8ae801891d7b3fdae2f6e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:9600c6310040af533d8d1920 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-q3j6-qgpj-74h6:pkg:2d0d5c8fc1bb62c4e3b44b2a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2w6w-674q-4c4q:pkg:d25708df68737694eb8e6977 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-qj8w-gfj5-8c6v:pkg:7d87d343aa0c80bd7734851a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2qvq-rjwj-gvw9:pkg:bde04755dd174b8acbe6de92 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-6g55-p6wh-862q:pkg:be20184562ed7ac60b9bb3c5 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2g4f-4pwh-qvx6:pkg:e75f751e62b1e8418f7d80f3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-52cp-r559-cp3m:pkg:b50fc3b7dc4817b2367e97d7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh29-5h37-fv8m:pkg:be84c0d3fc58da2798a815e5 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:006e2a19c763cc0fc17b9679 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:80dc2988b9d15a40674cea67 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-37qj-frw5-hhjh:pkg:e687e97ada633175cf3a9dbc applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4x5r-pxfx-6jf8:pkg:4b1c458623d5edd1e246a805 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:a9b17cadf83e3a5de547592b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8fgc-7cc6-rx7x:pkg:f80ec8e25f2f9f2ce4de54ab applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7rx3-28cr-v5wh:pkg:2d05cf734c06fd6d1e77b848 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fv7c-fp4j-7gwp:pkg:43dd868b8e2242ac0ba9d6d7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5c6j-r48x-rmvq:pkg:9695ebfe7ac51867550b15ed applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.monkey-patch · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: javascript-xray-structured-weakness · Execution scope: runtime

    Source: dist/index.js:77

  • Dependency advisory GHSA-f886-m6hf-6m8v:pkg:3c9cac5b1efe1960955c0ea1 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-c2c7-rcm5-vvqj:pkg:09f761f2e2a83fdc7890eb5a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:854982e350d33df8baa91ad9 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3v7f-55p6-f55p:pkg:972939a004a2a625fbda61c7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3mfm-83xf-c92r:pkg:146840b9eb3231ae1d463c20 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-38r7-794h-5758:pkg:3e2169c05cd6e65b3694dd1d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-wf6x-7x77-mvgw:pkg:c54fb3802e9d37bdf9527043 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v56q-mh7h-f735:pkg:85f01818ba1fa2d535c8fe80 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

Contextual expected matches (10)

JavaScript analysis reported javascript.xray.unsafe-regex

Expected behavior · high confidence

The flagged patterns are standard data-validation regular expressions from bundled third-party libraries. They are normal and not a security concern.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The unsafe-regex signal matches validation regexes for emails, IPs, domains, ISO durations, and base64 patterns bundled from libraries like Zod. These are standard static validation patterns embedded in a generated bundle, not attacker-controlled or ReDoS-exploitable in this context.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

A bundled library checks a configuration variable for its own logging. No sensitive data is collected or sent anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The serialize-environment signal corresponds to bundled library code checking process.env.LOG for logging configuration. No environment variables are serialized, exfiltrated, or sent to any external destination. This is a static-analysis artifact from a dependency, not a credential-theft data flow.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
generated
Source
dist/index.js:77

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

The file looks hard to read because it was minified for performance by a build tool, not because someone is hiding malicious code.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code. The match applies to this repository.

Contextual assessment: The obfuscated-code signal is triggered by the minified, webpack-bundled output in dist/index.js. Minification and bundling produce short variable names and dense code, which static analysis flags as obfuscation. This is a generated artifact, not intentionally concealed code.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.unsafe-import

Expected behavior · high confidence

The flagged imports are internal build-tool module loading, not downloads of unknown code.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-import. The match applies to this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-import
File role
generated
Source
dist/index.js:77

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged links are standard web-standard addresses used for creating SVG elements and defining data schemas. They are completely normal.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The shady-link signal matches W3C namespace URIs (SVG, XHTML, MathML, XLink, XML), JSON Schema draft URIs, and React's safety pattern that replaces javascript: URLs with throw statements. All are standard, well-known constants used for DOM creation and schema generation, not suspicious external endpoints.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
generated
Source
dist/index.js:30

JavaScript analysis reported javascript.download-to-execution

Expected behavior · medium confidence

The file contains both networking code and code-processing code because it bundles many libraries together. There is no evidence that downloaded data is fed into code execution.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution. The match applies to this repository.

Contextual assessment: The download-to-execution signal fires because the large generated bundle contains both fetch/XHR primitives (from bundled HTTP libraries) and code-execution sinks (from bundled transpiled generators and eval-like patterns) somewhere in the same file. No evidence shows a data flow from a network response into a code-execution sink. The co-occurrence is a static-analysis artifact of bundling many libraries into one file.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
generated
Source
dist/index.js:1-77

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

The flagged code actively protects against prototype pollution and uses standard JavaScript patterns from bundled libraries. No vulnerability is demonstrated.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution. The match applies to this repository.

Contextual assessment: The prototype-pollution signal matches __proto__ references that are defensively handled. The XML parser renames __proto__ to #__proto__ to prevent pollution, and the many Object.setPrototypeOf / __proto__ assignments are transpiled generator-function helpers from bundled libraries. No attacker-controlled property assignment reaches Object.prototype.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/index.js:60

JavaScript analysis reported javascript.xray.suspicious-literal

Expected behavior · high confidence

The flagged text fragments are normal parts of minified bundled libraries, not hidden malicious content.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.suspicious-literal. The match applies to this repository.

Contextual assessment: The suspicious-literal signal is triggered by the dense, minified content of the generated bundle. The literals visible in the evidence are regex patterns, namespace strings, and JSON.stringify calls from bundled libraries. No encoded payloads, hidden commands, or suspicious constants are demonstrated.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.suspicious-literal
File role
generated
Source
dist/index.js:1

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

This extension includes a node that lets you run your own JavaScript code as part of a visual flow. This is an intentional feature, clearly labeled as dangerous, and requires you to explicitly enable it before it can run. It only runs code you write yourself.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.

Contextual assessment: The Execute JS Code node uses new Function to run user-authored JavaScript from the flow's node data. This is a deliberate, disclosed feature of a visual automation tool. The node is marked isDangerous: true, and per the project's README, dangerous nodes are gated behind an explicit Allow Dangerous toggle that the user must enable per flow. The executed code is authored by the user in the visual editor, not received from an external or untrusted source. No concealed execution, exfiltration, or persistence beyond the extension's stated purpose is demonstrated.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
production
Source
src/components/nodes/ExecuteJsNode/definition.ts:27

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

The If node has an advanced mode that lets you write your own condition logic in JavaScript. This is an intentional feature, clearly labeled as dangerous, and requires you to explicitly enable it. It only runs code you write yourself.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.

Contextual assessment: The If node's advanced mode uses new Function to evaluate user-authored condition code from the flow's node data. This is a deliberate, disclosed feature. The node is marked isDangerous: true and is gated behind the Allow Dangerous toggle per the README. The condition code is authored by the user within the visual editor. No concealed execution, external data injection, or exfiltration is demonstrated.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
production
Source
src/components/nodes/IfNode/definition.ts:87

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity