TavernKeeper Scan Report

MaxiPawlowski/story-orchestrator

Commit 6076a7b Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 111 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
generated
Source
dist/index.js:6041
Deterministic technical evidence (89)
  • Dependency advisory GHSA-52cp-r559-cp3m:pkg:6f23b62026565fe6be6bd0de applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8452-54wp-rmv6:pkg:e4642f9d6258639db4a7c687 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-qffp-2rhf-9h96:pkg:b8a9dfa218123c667676179f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-qx2v-qp2m-jg93:pkg:d0433ccd51b55fc561da06bf applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-9cx6-37pm-9jff:pkg:ca52f57e7f6518348696e910 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8fgc-7cc6-rx7x:pkg:9ed07685ff5464171a0c11fb applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v6h2-p8h4-qcjw:pkg:954583494f7b71625ae8e6ee applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-58qx-3vcg-4xpx:pkg:464f1e56f88977dff15c5c23 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-48c2-rrv3-qjmp:pkg:15fc6ff22ccf7f2f103da797 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-38r7-794h-5758:pkg:37971723a11596456e55108b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-83g3-92jg-28cx:pkg:36f09712c5b19d62e2f59e39 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh29-5h37-fv8m:pkg:0b3a8eee8f9e6aaeac4bb535 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-23c5-xmqv-rm74:pkg:732c7481baa8e54386dfde00 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-w8wr-v893-vjvp:pkg:7da9495751fdc3bf9c299678 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-h67p-54hq-rp68:pkg:4638514cdacac77a40520d5f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:30da7db405d2e49715cb0ed6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:567c541f015fe4079ca9b17e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4c8g-83qw-93j6:pkg:1372faecb5851c2db1a935f0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r292-9mhp-454m:pkg:8aad2ce7479d51345c7e63a2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-w5hq-g745-h8pq:pkg:0112c5c21fbae77eed5d9af2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-23c5-xmqv-rm74:pkg:28c6f8e6010383b649a97a01 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3v7f-55p6-f55p:pkg:6567e5dee65459862e18aa65 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:c6056f5a45897dd10bfacade applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-6rw7-vpxm-498p:pkg:a8fa7e6b6947daa0b293c7df applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-395f-4hp3-45gv:pkg:1757fe298c80e943f960ee03 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-q3j6-qgpj-74h6:pkg:72c95ab6d027fa66d4c2567c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-442j-39wm-28r2:pkg:c54738cea96a333e19b8bd79 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:3dba9a3760f7e2f0b1fe3fa6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-xhpv-hc6g-r9c6:pkg:4114756074b3c1883ca427a6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7r86-cg39-jmmj:pkg:1a39cca405ef708861dee501 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mp7j-qc5w-4988:pkg:37bd18871c4a0a8dd7040038 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-q8mj-m7cp-5q26:pkg:c8139145098bf70d387ab548 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-34x7-hfp2-rc4v:pkg:7d77323718139b4267d31b2f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-w7jw-789q-3m8p:pkg:e759b74ebc110bc24a2525fe applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:a3638530d49c16954a754a83 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fv7c-fp4j-7gwp:pkg:31e02f2120b5c9c2060db33d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3ppc-4f35-3m26:pkg:173c1b2fab8e025126fb982c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:309438d8c981844c76003c01 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r6q2-hw4h-h46w:pkg:2f480be16e90e43ab1f41308 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-52cp-r559-cp3m:pkg:3814c2b152ab4147749d95d0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8x88-c5mf-7j5w:pkg:b62ceba241cb26d52e12cb4d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-xjpj-3mr7-gcpf:pkg:2c93c7ce30edf86304d17bbe applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-f886-m6hf-6m8v:pkg:16af9086b5e4ae9e3d4dc665 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v39h-62p7-jpjc:pkg:33e1140242e3fdb4577a5fde applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-968p-4wvh-cqc8:pkg:6997b5ed014d2e1ffec99f16 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7r86-cg39-jmmj:pkg:fa706fb036ae029fca4e7e55 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-gvwx-54wh-qm9j:pkg:9f7caa8dc32d63903b95a9a9 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-23c5-xmqv-rm74:pkg:2b0446bb17de561f11339ddb applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:80901b2eedb4ca6c2d61fee9 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2w6w-674q-4c4q:pkg:d25708df68737694eb8e6977 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-qj8w-gfj5-8c6v:pkg:7d87d343aa0c80bd7734851a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2qvq-rjwj-gvw9:pkg:bde04755dd174b8acbe6de92 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-6g55-p6wh-862q:pkg:be20184562ed7ac60b9bb3c5 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2g4f-4pwh-qvx6:pkg:8950845d54c4e7bb7af09309 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mjf5-7g4m-gx5w:pkg:3422b85313f25cc886ddda3d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-9ppj-qmqm-q256:pkg:1639a1de3213e0c21e655085 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-h67p-54hq-rp68:pkg:2379448cd276b8a7bb959cec applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:19b149914c26cb2c9c5de439 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.prototype-pollution · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: javascript-xray-structured-weakness · Execution scope: runtime

    Source: dist/index.js:5908

  • Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:936f2f623c05148e5153dbfe applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:006e2a19c763cc0fc17b9679 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:80dc2988b9d15a40674cea67 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rf6f-7fwh-wjgh:pkg:1ad66953e1a5c36ecde1d7df applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2g4f-4pwh-qvx6:pkg:cad7e9fb17eb5405be0d1fe2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3ppc-4f35-3m26:pkg:5ba4c6c0457aee43f20e933f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-vmf3-w455-68vh:pkg:dd6d5893824d975d2c6210e6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4x5r-pxfx-6jf8:pkg:25699e8af93adc546e42c0c5 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-xv26-6w52-cph6:pkg:00ec2d8e386430e98d725c05 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-25h7-pfq9-p65f:pkg:27d1ccf82c346af697c968b5 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:65e56d3e94b4e1a92191e9c1 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:a9b17cadf83e3a5de547592b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-w5hq-g745-h8pq:pkg:65a116c32d8f4bb803d2234c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-w7fw-mjwx-w883:pkg:009dcf371fb88cd6a5335a7e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7r86-cg39-jmmj:pkg:f702a3e4a998c2fa1a127011 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-f886-m6hf-6m8v:pkg:db05cad6d25aec0390d39a8c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7rx3-28cr-v5wh:pkg:2d05cf734c06fd6d1e77b848 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.monkey-patch · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: javascript-xray-structured-weakness · Execution scope: runtime

    Source: dist/index.js:1753-1755

  • Dependency advisory GHSA-5c6j-r48x-rmvq:pkg:9695ebfe7ac51867550b15ed applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-c2c7-rcm5-vvqj:pkg:6159a1838ee53aace6ac3052 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:0546a3b9043a41cf17d6475f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-c2c7-rcm5-vvqj:pkg:09f761f2e2a83fdc7890eb5a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3ppc-4f35-3m26:pkg:5b0d86b7147a191050fb118c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-23hp-3jrh-7fpw:pkg:d289a4bb35ce0915785e983b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-96hv-2xvq-fx4p:pkg:788f1d7067e1308f3b84ebcc applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3v7f-55p6-f55p:pkg:972939a004a2a625fbda61c7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3mfm-83xf-c92r:pkg:146840b9eb3231ae1d463c20 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8qq5-rm4j-mr97:pkg:710f4f4c5e1ba205aa530c13 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4vvj-4cpr-p986:pkg:22c109a976fe8de7e59c9bb7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-48c2-rrv3-qjmp:pkg:a2b2de1b67a6232727d04ad2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

Contextual expected matches (18)

JavaScript analysis reported javascript.xray.unsafe-regex

Expected behavior · high confidence

A familiar library helper for parsing dotted property paths appears in the bundled output. The complex regex triggered a scanner signal, but no actual security issue is shown.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The same lodash stringToPath regex appears in the raw webpack bundle. It is a standard property-path parsing utility with no demonstrated attacker-controlled input or reachable exploitation path in the supplied evidence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
generated
Source
dist/111.index.js:1

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

The scanner noticed both image-loading code and module-loading code in the same bundle, but they are unrelated. No downloaded content is executed as code. This is a normal bundled web application.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution. The match applies to this repository.

Contextual assessment: The scanner correlated a network primitive with a code-execution sink in the same representation. The network primitive is new Image() with src assignment for image loading in React/cytoscape, and the execution sink is webpack's module factory call pattern. These are unrelated patterns in a large bundle; there is no data flow where network-retrieved content is passed to a code execution sink. The bundle is a standard React + cytoscape + lodash production build.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged code is part of a graph-drawing library bundled into the extension. It checks whether an image is an inline data image before deciding how to load it. This is normal image-handling behavior and does not send data anywhere or do anything harmful.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The flagged line is inside the getCachedImage function of the bundled cytoscape graph library. The string literal data is a protocol prefix check used to determine whether to set crossOrigin on an Image element. Data URIs should not receive crossOrigin attributes, so the code compares the image source prefix against this literal and only sets crossOrigin for non-data-URI sources. This is standard, benign image-loading logic from a widely used visualization dependency. There is no network destination, no exfiltration, no obfuscation, and no attacker-controlled data flow at this location.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
generated
Source
dist/index.js:20176

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged links are standard web-standard addresses for SVG and XML rendering, not suspicious destinations. They are identifiers used internally by the browser, not places the code contacts.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The 21 shady-link occurrences are standard W3C namespace URIs (SVG, MathML, xlink, XML) used by React's DOM rendering code for createElementNS and setAttributeNS calls. These are well-known specification URIs, not external endpoints. No data is sent to these URIs; they are namespace identifiers used by the browser's DOM API.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
generated
Source
dist/index.js:9

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The scanner flagged a common coding pattern used to copy objects. The code copies story-state objects for comparison, not credentials or system information. This is a normal programming technique.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The serialize-environment signal matched JSON.parse(JSON.stringify(e)) calls, which are deep-clone utilities used for state comparison and immutability in the extension's checkpoint and blackboard logic. No environment variables, process state, or credentials are serialized. The pattern is a common clone-by-serialization idiom in bundled application code.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
generated
Source
dist/index.js:9

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

The extension ships a minified build file where variable names are shortened and helper code is bundled together. A scanner mistook this normal bundler output for deliberate obfuscation. The code is just standard library and project code compressed for delivery.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code. The match applies to this repository.

Contextual assessment: The scanner flagged an obfuscated-code signal on a webpack production bundle. The visible source shows standard minified bundler output: class creation helpers, iterator/async helpers, type-checking utilities, color parsing tables, and lodash-style memoized functions. Short variable names and helper boilerplate are expected from production minification, not from obfuscation techniques. No string encoding, eval-based decoding, concealed logic, or opaque control flow is present in the supplied context.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.unsafe-regex

Expected behavior · high confidence

This is a standard helper from a common library (lodash) that splits strings like a.b[0] into path segments. The scanner flagged the complex-looking regex, but it is a routine bundled utility with no demonstrated security problem.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The flagged regex is the well-known lodash stringToPath pattern used to parse dotted and bracketed property paths such as a.b[0].c. It is a standard, widely-tested utility bundled into the generated webpack output. No attacker-controlled input path or ReDoS trigger is demonstrated in the supplied context; the regex operates on author-supplied property-path strings within the extension's own state-management logic.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
generated
Source
dist/111.index.js:2

JavaScript analysis reported javascript.opengrep.tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

A bundled utility library uses a standard JavaScript trick to access the global object. The code passed to it is a fixed, hardcoded string, not anything user-supplied or dynamic. This is a normal library pattern, not a security issue.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.opengrep.tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.

Contextual assessment: The matched pattern is `Function("return this")()` at line 711 inside the `Oe()` function, which is a well-known lodash utility for resolving the global object in strict-mode environments. The Function constructor receives a static string literal with no attacker-controlled input. This is a standard lodash pattern bundled into the production build and does not constitute dynamic code execution from untrusted input.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.opengrep.tavernkeeper.dynamic-execution.javascript-eval
File role
generated
Source
dist/index.js:711

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

This file is a packaged bundle of a standard graph-layout library used to arrange visual checkpoint diagrams. The pattern that triggered the scanner is just the normal way the packaging tool loads its own modules, not any form of hidden or dynamic code execution. The code does math to position nodes and edges on screen and does not run any outside or user-supplied code.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.

Contextual assessment: The scanner matched dynamic-execution patterns on this minified webpack chunk, but the matched code is the standard webpack module runtime wrapper: e[n].call(o.exports, o, o.exports, t). This is webpack's normal mechanism for invoking module factory functions and is present in every webpack bundle. The chunk content itself is the cytoscape-dagre layout plugin and the dagre graph-layout library, performing graph ranking, ordering, and coordinate positioning. No eval(), new Function(), setTimeout(string), or other dynamic code execution is present. The code operates on in-memory graph data structures and produces layout coordinates, which matches the project's stated use of cytoscape and cytoscape-dagre for checkpoint graph visualization.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
generated
Source
dist/111.index.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged code is part of the React library bundled into the extension. It contains standard web-library plumbing, including a built-in safety check that blocks dangerous javascript: links. There is no evidence of any suspicious or malicious link handling.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The scanner's shady-link signal matches standard React DOM internals bundled into the generated output. The cited context shows React's well-known javascript: URL sanitizer (regex Ot and function Nt) that blocks javascript: URLs by replacing them with a throwing error stub, plus standard XML namespace constants (SVG, MathML, xlink, XML) used during element creation. These are defensive and rendering-internal behaviors of the React dependency declared in package.json, not project-authored network calls, exfiltration, or suspicious destinations.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
generated
Source
dist/index.js:1128

Gitleaks reported generic-api-key

Expected behavior · high confidence

A secret scanner flagged the word 'key' in a planning document, but it is referring to JSON field names in test files, not a password or API key. There is no real credential here.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key. The match applies to this repository.

Contextual assessment: The gitleaks generic-api-key rule matched on line 33 of a documentation file. The matched line describes test fixture JSON structure using the word 'key' in the context of expected-delta field names, not a credential. No secret value is present in the supplied source text; the scanner explanation confirms the matched value was removed because it was a pattern hit on ordinary prose, not an actual API key.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
documentation
Source
docs/plans/v2/03-extractor.md:33

JavaScript analysis reported javascript.xray.suspicious-literal

Expected behavior · high confidence

The scanner flagged a large block of text, but it is just CSS styling code generated by the Tailwind CSS framework. It contains only visual styling rules for the extension's user interface — no code, no network activity, and nothing suspicious.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.suspicious-literal. The match applies to this repository.

Contextual assessment: The flagged line 1 is a webpack CSS module loader entry that pushes a large CSS string into the module cache. The CSS content is Tailwind CSS v4.1.13 output, containing standard utility classes (layout, spacing, typography, colors, shadows, transitions) and Tailwind's specificity-bumping not(#) selector pattern. The suspicious-literal signal is triggered by the large escaped string literal, but the content is purely declarative CSS with no executable JavaScript, no network calls, no credential access, and no obfuscation. It is generated build output from a widely used CSS framework.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.suspicious-literal
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This line sets a default local address for the Ollama AI tool when the user has not specified their own. It is a standard and expected pattern for extensions that connect to local AI services. The user can change this address in the extension settings, and the connection is used only to compute text embeddings for memory deduplication as described by the project.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The scanner flagged line 91 which sets a default embedding endpoint URL. The value is a local Ollama default address used as a fallback when the user has not configured a custom embedding URL in extension settings. The code reads the user-configurable base URL, model name, API key, and source type from extension settings. Network calls are made to either an Ollama embed endpoint or an OpenAI-compatible embeddings endpoint, both of which directly match the stated project purpose of semantic memory deduplication. The API key is sourced from extension settings and sent only as a standard Bearer header for the OpenAI-compatible path. No hardcoded external destinations, no credential exfiltration, and no concealed network behavior are present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
vendored
Source
vendor/smart-memory/embeddings.js:91

JavaScript analysis reported javascript.xray.monkey-patch

Expected behavior · high confidence

The scanner flagged standard JavaScript class definitions that use the prototype pattern. This is how JavaScript libraries normally define methods on their own objects, not malicious modification of other code.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.monkey-patch. The match applies to this repository.

Contextual assessment: The 40 monkey-patch signals correspond to standard prototype-based class definitions in bundled libraries (heap data structure, cytoscape prototypes, lodash utilities). Assignments like e.prototype.push = function(){} and o[c] = o[c] || function(){} are normal JavaScript class construction, not runtime patching of built-in or third-party objects to alter behavior maliciously.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.monkey-patch
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The build script checks a standard environment variable to decide whether to create a development or production build. This is normal practice and does not read, copy, or send any private information.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The flagged line reads process.env.NODE_ENV to select webpack's build mode (development vs production) and devtool source-map setting. This is a standard, ubiquitous webpack configuration pattern in a build-tooling file that is not shipped to users. No credentials, secrets, or sensitive environment variables are accessed, serialized, or transmitted. The scanner's serialize-environment rule triggered on the process.env reference, but the actual data flow is a single build-mode boolean check with no exfiltration or persistence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
webpack.config.js:13

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

The scanner saw references to __proto__ and related property names, but the code is actually the library's built-in protection that blocks prototype pollution. This is defensive code, not a vulnerability.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution. The match applies to this repository.

Contextual assessment: The four occurrences flagged as prototype-pollution are lodash internal guards in modules such as 4974, 4218, 3360, and 3170. These functions explicitly check for and reject __proto__, constructor, and prototype keys before assignment, which is lodash's defensive mitigation against prototype pollution rather than an exploitable sink. No untrusted attacker-controlled input is shown reaching these functions in the supplied evidence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/111.index.js:1

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

The flagged code actually protects against prototype pollution rather than causing it. The libraries include safety checks that block dangerous property names. This is good practice, not a vulnerability.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution. The match applies to this repository.

Contextual assessment: The prototype-pollution signals matched defensive guards in lodash and cytoscape code: checks like __proto__!==e, and explicit returns when __proto__, constructor, or prototype are encountered during property traversal. Cytoscape also includes an explicit warning about illegal types that could lead to prototype pollution. These are protective measures, not exploitative mutations of Object.prototype.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
dist/index.js:7

JavaScript analysis reported javascript.xray.unsafe-regex

Expected behavior · high confidence

A code scanner flagged some regular expressions (text-matching patterns) as potentially slow. These patterns are used to detect scene transitions and other text features in roleplay messages. They are straightforward match patterns applied to individual chat messages and do not pose a security risk. At most, extremely long messages could cause a tiny slowdown, but no real harm is demonstrated.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The JS-X-Ray unsafe-regex signal fired on line 461 and reported 6 occurrences across the parsers file. The flagged patterns are alternation-based regular expressions used to detect transitional phrases, scene breaks, and relationship-line formats in AI-generated roleplay text. They use literal string alternations with optional whitespace and word-character groups. The character classes involved (word characters vs whitespace) are disjoint, preventing ambiguous backtracking. The patterns are applied to individual chat messages, which are bounded in length. No catastrophic backtracking path is demonstrated in the supplied code, and worst-case behavior would be a negligible processing delay on a single message, not a concrete security harm.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
vendored
Source
vendor/smart-memory/parsers.js:461

Related contextual observations

Webpack module factory invocation is standard runtime behavior

low risk · high confidence

The packaging tool loads its modules by calling their functions directly, which is completely normal and expected. This is not a security issue.

Technical assessment

The expression e[n].call(o.exports, o, o.exports, t) is webpack's standard module execution pattern where each module's factory function is invoked with the module's exports context. This is identical across all webpack bundles and is not a security-relevant dynamic execution primitive.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Cytoscape image cache crossOrigin handling is standard library behavior

low risk · high confidence

The graph library loads images for display and correctly handles inline images versus external images. Nothing here is suspicious.

Technical assessment

The getCachedImage function creates Image objects for graph node backgrounds and conditionally assigns crossOrigin based on whether the source is a data URI. This is consistent with normal cytoscape rendering code and poses no security concern in the extension context.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity