TavernKeeper Scan Report

Coneja-Chibi/VectHare

Commit 3339e64 Reviewed

16 material concerns identified.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 16 material 38 low

What this review found

Dependency advisory GHSA-5xrq-8626-4rwp applies

Material concern · low confidence

A scanner found a critical advisory, but the supplied evidence does not identify the package, version, or whether users can reach the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.

Contextual assessment: The advisory match is in a production lockfile, but package identity, installed version, advisory condition, runtime reachability, and attacker-controlled input are omitted. A critical scanner label alone cannot establish immediate danger.

Impact: high · Exploitability: plausible

Developer action: Provide the matched package and installed version, then assess whether production runtime reaches the vulnerable code before upgrading or documenting the finding.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5xrq-8626-4rwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v6wh-96g9-6wx3 applies

Material concern · low confidence

A scanner found a medium-severity dependency advisory, but there is not enough detail to tell whether the extension is affected during normal use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.

Contextual assessment: The evidence records an advisory match but removes package details and provides no version, reachability, input-flow, or impact information. The lockfile is production-role, yet the visible root entries are test-only, so dependency placement is also unresolved.

Impact: medium · Exploitability: plausible

Developer action: Provide the matched package and installed version, then verify runtime reachability and upgrade if the advisory affects shipped execution.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6wh-96g9-6wx3
File role
production
Source
package-lock.json

Dependency advisory GHSA-25h7-pfq9-p65f applies

Material concern · low confidence

A high-severity dependency warning was reported, but the evidence does not show what component is involved or whether normal users can trigger it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-25h7-pfq9-p65f to a dependency declared by this repository.

Contextual assessment: Only the advisory identifier and scanner classification are supplied. No package/version, vulnerable range, runtime reachability, attacker-controlled input, or concrete harm is available.

Impact: high · Exploitability: plausible

Developer action: Identify the package and installed version and determine whether the vulnerable path is shipped and reachable before applying a targeted upgrade.

Scanner
osv-scanner 2.4.0
Rule
GHSA-25h7-pfq9-p65f
File role
production
Source
package-lock.json

Dependency advisory GHSA-4w7w-66w2-5vf9 applies

Material concern · low confidence

A medium-severity advisory was detected, but the supplied report omits the information needed to decide whether users are exposed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.

Contextual assessment: The match lacks package identity, installed version, vulnerable behavior, runtime reachability, and attacker-input analysis. The result is therefore a material unresolved dependency issue, not a confirmed exploitable vulnerability.

Impact: medium · Exploitability: plausible

Developer action: Identify the affected package and version and assess whether it is runtime-reachable in the shipped extension.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4w7w-66w2-5vf9
File role
production
Source
package-lock.json

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Material concern · low confidence

A high-severity dependency warning exists, but the evidence does not establish that the extension actually uses the vulnerable behavior.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: The scanner output omits package/version and all runtime data-flow details. Severity and confidence describe the advisory match, not exploitability in this project.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version and validate production reachability and exploit conditions before upgrading or documenting an exception.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Material concern · low confidence

A high-severity dependency issue was flagged, but the supplied evidence cannot show how a user could encounter it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: There is only an advisory identifier and scanner classification. Package identity, version, vulnerable range, runtime reachability, attacker control, and concrete impact are unavailable.

Impact: high · Exploitability: plausible

Developer action: Provide package/version details and verify whether the advisory affects runtime code included and reachable by the extension.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-28wg-ghj8-5hjv applies

Material concern · low confidence

A high-severity advisory was reported, but the report lacks enough detail to determine whether it affects real extension use.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-28wg-ghj8-5hjv to a dependency declared by this repository.

Contextual assessment: The supplied evidence does not include package/version, advisory semantics, runtime reachability, attacker-controlled input, or resulting harm. It supports follow-up, not a confirmed immediate exploit.

Impact: high · Exploitability: plausible

Developer action: Identify the dependency and installed version and assess whether the vulnerable code is reachable in production execution.

Scanner
osv-scanner 2.4.0
Rule
GHSA-28wg-ghj8-5hjv
File role
production
Source
package-lock.json

Dependency advisory GHSA-7r86-cg39-jmmj applies

Material concern · low confidence

A high-severity dependency warning was found, but the supplied material does not show whether users are exposed during ordinary operation.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: Only the advisory identifier and scanner severity are available. The package, installed version, vulnerable behavior, reachability, and attacker-input path are absent.

Impact: high · Exploitability: plausible

Developer action: Identify the affected package and installed version and test whether normal production flows reach the vulnerable code.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Material concern · low confidence

A scanner found a known issue in a dependency, but the supplied evidence does not identify the package or show whether the extension uses the affected code.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: The advisory match is high-confidence scanner evidence, but package identity, installed version, vulnerability mechanism, and runtime reachability were removed. Impact and exploitability therefore cannot be established beyond a conditional dependency risk.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-96hv-2xvq-fx4p applies

Material concern · low confidence

A scanner found a high-severity dependency issue, but the supplied evidence does not show which package is affected or whether users can reach the vulnerable behavior.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-96hv-2xvq-fx4p to a dependency declared by this repository.

Contextual assessment: The scanner reports a high-severity advisory for a declared dependency, but package details, version range, reachability, attacker-controlled input, and concrete impact are unavailable.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-96hv-2xvq-fx4p
File role
production
Source
package-lock.json

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Material concern · low confidence

A scanner found a high-severity dependency issue, but the supplied evidence does not establish whether this affects normal extension operation.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: The advisory match is not enough to determine practical exposure because the affected package, installed version, vulnerable path, and attacker input path are omitted.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Material concern · low confidence

A scanner reported a high-severity issue in a dependency, but there is not enough information to tell whether it creates a usable attack against this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: Package identity, version, advisory behavior, runtime reachability, and attacker control are unavailable, so this remains a conditional material dependency concern rather than an immediate-danger finding.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-58qx-3vcg-4xpx applies

Material concern · low confidence

A scanner found a known dependency issue, but the evidence does not reveal whether the affected functionality is used by the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-58qx-3vcg-4xpx to a dependency declared by this repository.

Contextual assessment: The scanner match lacks the dependency name, installed version, vulnerability details, and runtime data flow needed for contextual severity assessment.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-58qx-3vcg-4xpx
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Material concern · low confidence

A scanner reported a high-severity dependency problem, but the supplied material cannot show whether it can harm users of this extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: The advisory severity is not sufficient for an immediate-danger conclusion; affected package, version, reachability, input control, and concrete harm are missing.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-2v37-7h3g-55p8 applies

Material concern · low confidence

A scanner found a high-severity issue in a dependency, but the evidence does not identify an exposed feature or attack path.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2v37-7h3g-55p8 to a dependency declared by this repository.

Contextual assessment: The supplied record omits the package, installed version, affected code path, runtime use, and attacker-controlled input, preventing a more specific assessment.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2v37-7h3g-55p8
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Material concern · low confidence

A scanner reported a high-severity dependency issue, but the supplied evidence does not show whether normal users can trigger it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: The match is high-confidence at scanner level, while package identity, installed version, vulnerability conditions, runtime reachability, and impact remain unspecified.

Impact: medium · Exploitability: plausible

Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json

Minor cautions

JavaScript analysis reported javascript.xray.obfuscated-code

Minor caution · low confidence

The scanner noticed a possible obfuscated-code pattern, but the supplied material does not show what was matched or indicate harmful behavior. Obfuscation can make future review harder, so the affected code should be explained or simplified.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The only supplied finding is a low-confidence static obfuscation signal. The provided source excerpt shows ordinary module imports and UI-manager documentation, while matched literals were not retained. There is no evidence here of concealed execution, credential theft, unauthorized persistence, or external exfiltration. Because the flagged representation and relevant code path are unavailable, intent and exact behavior cannot be fully assessed.

Impact: low · Exploitability: unlikely

Developer action: Provide the flagged JavaScript representation or scanner details identifying the matched construct, and document or remove any intentional obfuscation.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
ui/ui-manager.js:1

JavaScript analysis reported javascript.xray.shady-link

Minor caution · medium confidence

The extension sends provider connection details and, when configured, an API key to the local plugin service so it can test or generate embeddings. That fits its vector-search purpose, but storing the key in extension settings and allowing a user-selected endpoint deserves extra protection.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The flagged code constructs provider-specific request parameters. For the BananaBread provider it selects either a user-configured alternate endpoint or a localhost default and includes the configured provider API key in the request body. The evidence shows intentional provider integration and no evidence of an unrelated destination, concealment, or exfiltration. The use of a configurable endpoint and plaintext HTTP default creates transport and credential-handling concerns, but does not establish malicious behavior from the supplied context alone.

Impact: medium · Exploitability: plausible

Developer action: Document the endpoint and credential handling clearly; prefer the host application's secret storage where available, and use secure transport for configurable remote endpoints.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
diagnostics/production-tests.js:72

JavaScript analysis reported javascript.xray.obfuscated-code

Minor caution · low confidence

The scanner noticed a possible pattern associated with hard-to-read JavaScript, but the supplied evidence does not show what caused it or whether it hides harmful behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The candidate is based on a low-confidence obfuscation signal, while the supplied source context contains only the beginning of a production debug-modal file and no retained matched literals or complete data-flow evidence. The visible comments describe diagnostics for a RAG search pipeline, which is consistent with the file's stated role, but the available evidence cannot assess the remainder of the 74 KB artifact or determine whether any obfuscation is intentional and benign. This is insufficient to establish malicious execution, credential access, exfiltration, or concealed persistence; the incomplete visibility is a review limitation rather than evidence of safety.

Impact: low · Exploitability: unlikely

Developer action: Provide the complete file contents or the scanner's retained matched regions for review, and document any intentional generated or minified sections.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
ui/search-debug.js:1

Dependency advisory GHSA-6g55-p6wh-862q applies

Minor caution · low confidence

A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.

Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6g55-p6wh-862q
File role
production
Source
package-lock.json

Dependency advisory GHSA-67mh-4wv8-2f99 applies

Minor caution · low confidence

A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-67mh-4wv8-2f99 to a dependency declared by this repository.

Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-67mh-4wv8-2f99
File role
production
Source
package-lock.json

Dependency advisory GHSA-rf6f-7fwh-wjgh applies

Minor caution · low confidence

A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh to a dependency declared by this repository.

Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rf6f-7fwh-wjgh
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · low confidence

A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Minor caution · low confidence

A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-mw96-cpmx-2vgc applies

Minor caution · low confidence

A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mw96-cpmx-2vgc to a dependency declared by this repository.

Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mw96-cpmx-2vgc
File role
production
Source
package-lock.json

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · low confidence

A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
package-lock.json

Dependency advisory GHSA-qx2v-qp2m-jg93 applies

Minor caution · low confidence

A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.

Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.

Impact: low · Exploitability: unlikely

Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qx2v-qp2m-jg93
File role
production
Source
package-lock.json

Dependency advisory GHSA-fx2h-pf6j-xcff applies

Minor caution · low confidence

A scanner found a known issue in one dependency, but the supplied evidence does not identify the package or show that the extension uses the vulnerable code. The visible lockfile section lists only testing tools as direct development dependencies.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.

Contextual assessment: The advisory match is metadata indicating a declared dependency, but the package identity, installed version, vulnerable component, runtime reachability, attacker-controlled input, and concrete impact are omitted. The shown root manifest contains only development dependencies, so production exposure cannot be established from the supplied context. This warrants remediation and dependency verification, not an immediate-danger classification.

Impact: low · Exploitability: unlikely

Developer action: Identify the exact affected package and installed version, determine whether it is production-reachable or only a development/test dependency, then update or replace it if the advisory applies.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fx2h-pf6j-xcff
File role
production
Source
package-lock.json
Expected scanner matches (26)

JavaScript analysis reported javascript.download-to-execution

Expected behavior · low confidence

The scanner found network-related and dynamic-execution patterns somewhere in a large user-interface file, but the supplied excerpt only shows diagnostic dialogs, console capture, report generation, and user-triggered fixes. It does not show downloaded content being executed.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: Review the omitted portions of the module and its imported diagnostics code to confirm whether any retrieved data reaches an executable sink; separate diagnostic UI rendering from actual execution.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.download-to-execution
File role
production
Source
ui/ui-manager.js:1017-3564

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · low confidence

The available evidence only reports a low-confidence scanner signal for obfuscation. It does not show hidden behavior, data theft, or harmful execution.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The supplied production source is text evidence, but the candidate contains no retained matched literals or code-flow details. Imports and the stated database-browser purpose are consistent with an extension managing vector collections; the obfuscation signal alone does not establish concealment or malicious behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
ui/database-browser.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · low confidence

The scanner flagged a network-related pattern, but the supplied line is only a test mock for a local service address. It does not show an external connection or secret transmission.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The candidate points to a test fixture configuring a local Ollama endpoint. The evidence contains no request execution, attacker-controlled destination, credential flow, or exfiltration behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
test
Source
tests/backends.test.js:34

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged fixed address is a local embedding-service fallback, which fits the extension’s stated vector-backend purpose and does not show data being sent to an unrelated destination.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The observed value is a localhost URL selected only for the bananabread provider when no alternate endpoint is configured. It is paired with provider-specific API parameters and is not evidence of a concealed external connection.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
backends/standard.js:75

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · low confidence

This is a test-only local API address used to imitate the extension's configured service. The supplied evidence does not show data leaving the user's machine.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The flagged value is a localhost API URL in mocked extension settings. It is test configuration rather than production network behavior, and no external destination or sensitive-data transfer is evidenced.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
test
Source
tests/backends.test.js:19

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged line selects a local service address for the configured embedding backend. This matches the extension’s purpose of supporting local model servers and does not show hidden communication.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The fixed address is used only as the default API endpoint for the explicitly selected Bananabread provider; an alternate configured endpoint can be used. The supplied evidence shows no concealment, unrelated destination, credential exfiltration, or execution behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
core/core-vector-api.js:224

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · low confidence

The available evidence only says an automated tool noticed a possible obfuscation pattern. It does not show what was hidden or that the extension performs harmful actions.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The candidate is a low-confidence static obfuscation signal with matched literals withheld. The supplied source context shows a production visualizer module with ordinary imports related to chunk metadata, vector operations, scenes, hashing, and host integration, but it does not establish concealed execution, credential access, exfiltration, persistence, or malicious update behavior. Because the complete file behavior and matched signal are not available, this is not evidence of malicious behavior by itself; targeted review is still appropriate if obfuscation remains present in the artifact.

Impact: none · Exploitability: unlikely

Developer action: Provide the scanner-matched literals or a readable, non-transformed representation and review any dynamic execution, network, storage, and credential-handling paths.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
ui/chunk-visualizer.js:1

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · low confidence

The supplied lines show ordinary temporal-memory calculations, but they do not include the code that caused the scanner signal. There is no evidence here of harmful behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The candidate is a low-confidence static obfuscation signal. The available source slice contains imports, comments, and simple mathematical functions consistent with the stated temporal-decay feature, with no visible concealment, external destination, credential handling, persistence, or execution. Because only lines 1–41 are supplied for an 18,358-byte production file, the flagged representation and remaining behavior cannot be fully assessed; this is an assessment of the candidate, not proof of the artifact's overall safety.

Impact: none · Exploitability: unlikely

Developer action: Provide the complete file or a sufficiently broad source slice so the flagged representation and any related data flows can be inspected.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
core/temporal-decay.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged value selects either the configured embedding service or a local default. This is part of sending text for vectorization, which matches the extension’s retrieval purpose; the supplied code does not show a hidden destination or concealed behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The code derives the embedding endpoint from a user-configurable setting, otherwise uses a local service address, then posts cleaned input text to an embeddings API. An optional configured API key is placed in the request authorization header. The scanner signal alone does not establish malicious networking, and the visible data flow is consistent with the documented embedding functionality.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
core/core-vector-api.js:447

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

When BananaBread is selected, the extension checks the configured server for available models. It may include the API key that the user entered so the server can authenticate the request. This matches the documented model-provider connection purpose.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The code constructs a server URL from user-controlled provider settings, defaults to a local BananaBread endpoint, and performs a GET request to its models endpoint. A configured provider API key is placed in an Authorization header for that same configured endpoint. The supplied evidence shows no unrelated destination, concealment, persistence, or exfiltration behavior; the fixed signal is consistent with an endpoint URL used by the provider health check.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
diagnostics/infrastructure.js:939

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · medium confidence

The flagged code sends chat text and a configured authentication key to a reranking service so the extension can improve search results. That matches the advertised RAG and reranking features. The supplied evidence does not show a hidden third-party destination, although the alternate address and key handling should be made explicit to users.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The function selects either a user-configured alternate endpoint or a localhost service, then posts the query, retrieved document text, and an API-key field through the host plugin route for reranking. This is proportionate to the documented optional reranking/backend functionality. The evidence does not establish covert exfiltration or malicious behavior, but it does not reveal the key's source or validate alternate-endpoint restrictions; those are disclosure and hardening concerns rather than demonstrated compromise.

Impact: low · Exploitability: unlikely

Developer action: Document the reranking endpoint and API-key handling clearly in the settings and README; ensure the key is sourced from user-configured state and is sent only to the intended local or explicitly configured backend.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
core/chat-vectorization.js:349

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This code prepares connection details for a locally configured model service. The detected link-like value is a local endpoint, and the key is included for the plugin request rather than sent to an unrelated destination.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The flagged value is an endpoint constructed for the BananaBread provider, defaulting to a local service address or a user-selected alternate endpoint. The same function adds the configured provider key to the request parameters. The supplied context shows provider-specific request preparation consistent with the extension's stated vector-embedding purpose, with no evidence of a fixed external destination, concealment, or unrelated exfiltration.

Impact: none · Exploitability: unlikely

Developer action: Review whether the BananaBread endpoint and API key must be sent in the request body; if required, document this clearly and prefer the host application's secret-handling facilities where available.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
diagnostics/production-tests.js:74

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · low confidence

The available evidence only says that an automated scanner noticed a possible obfuscation pattern. It does not show what was matched or demonstrate hidden, harmful behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The candidate is a low-confidence static obfuscation signal with matched literals omitted. The supplied source context contains only imports, comments, and exports, not the flagged representation or an observable suspicious data flow. Obfuscation alone is insufficient to infer malicious behavior or a vulnerability in this extension's collection-management purpose.

Impact: none · Exploitability: unlikely

Developer action: Provide the complete transformed JavaScript or the scanner's retained match details and surrounding source so the signal can be assessed.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
core/collection-loader.js:1

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · low confidence

The supplied material does not show meaningful code hiding or suspicious execution. The scanner result alone is too weak to establish a security problem.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: Only a low-confidence obfuscation signal is supplied, without matched content. The available source excerpt is readable, documented provider-selection code, and does not demonstrate concealed behavior, credential theft, or unrelated persistence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
backends/standard.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · low confidence

The scanner detected a link-like signal, but the actual matched value was withheld. The visible code displays configured provider or database endpoints in a report and does not show an unexplained connection.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The evidence identifies only a static scanner signal and explicitly omits the matched literal. Nearby supplied logic obtains endpoint values from extension settings for inclusion in a diagnostics report; it does not demonstrate a hidden destination, automatic transmission, credential collection, or execution. Because the literal and complete surrounding code are unavailable, intent and destination cannot be confirmed, but the candidate alone does not support a security finding.

Impact: none · Exploitability: unlikely

Developer action: Inspect the omitted literal and surrounding logic to identify the matched link and verify that it is an intentional provider, documentation, or user-configured endpoint rather than an undisclosed destination.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
ui/ui-manager.js:3232

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · low confidence

The scanner found a weak signal that some JavaScript may look unusual, but the supplied evidence does not show hidden behavior, stolen data, or a harmful destination. This file is the extension's main vectorization and retrieval logic, where complex generated or bundled-looking code can occur.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The candidate is based only on a low-confidence obfuscation heuristic. Supplied source context shows ordinary ES module imports for chat retrieval, vector storage, embedding backends, filtering, diagnostics, and request headers, all consistent with the stated RAG purpose. No obfuscated payload, concealed execution, credential exfiltration, persistence mechanism, or external destination is evidenced. The assessment is limited because the candidate metadata does not retain the matched literals or precise behavior, and the provided source excerpt is incomplete relative to the full file supplied by hash and size metadata only for scanner matching.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
core/chat-vectorization.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged link-like value is a local service address used for a supported provider connection, not a concealed outside destination.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The candidate is a fixed loopback HTTP endpoint selected only when the configured provider is BananaBread and no alternate endpoint is enabled. The surrounding code assembles provider parameters for plugin requests; the supplied evidence shows no external destination, credential transmission beyond that provider request, obfuscation, or covert execution.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
diagnostics/infrastructure.js:39

JavaScript analysis reported javascript.download-to-execution

Expected behavior · low confidence

The supplied excerpt shows ordinary browser UI and API activity for a database browser, but it does not show downloaded content being executed.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The candidate is based on a broad correlation between network retrieval and a possible execution sink within a large JavaScript representation. The supplied context shows a health check using fetch and extensive UI, import, export, and collection-management logic. It does not identify a specific retrieved response flowing into dynamic evaluation, command execution, or another executable sink. Because the excerpt is truncated before the candidate range ends, the conclusion is limited to the supplied evidence and does not establish malicious or vulnerable behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.download-to-execution
File role
production
Source
ui/database-browser.js:96-444

JavaScript analysis reported javascript.xray.encoded-literal

Expected behavior · high confidence

The flagged text is a normal test value used to check how collection identifiers are parsed. It does not perform hidden actions or send data.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.encoded-literal in this repository.

Contextual assessment: The candidate points to a fixed identifier string in a backend unit test. The surrounding test verifies parsing of a documented collection-ID format; no execution, decoding, persistence, or external data flow is shown at the flagged location.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.encoded-literal
File role
test
Source
tests/backends.test.js:680

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · low confidence

The supplied portion is a documented mathematical utility for comparing vectors, which fits the extension’s retrieval purpose. The scanner provided only a low-confidence obfuscation signal and retained no matching values; this evidence does not show hidden behavior, data collection, or secret handling.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The available source excerpt shows ordinary, readable vector-distance implementation with no dynamic execution, networking, persistence, credential access, or encoded payload. The candidate is based only on low-confidence scanner metadata, so it does not substantiate malicious obfuscation or a vulnerability in this production utility file.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
utils/vector-distance.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · low confidence

The flagged address is another local development endpoint in a test mock. Nothing supplied indicates that the extension contacts it unexpectedly or sends private information.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The evidence identifies a mocked local vLLM server URL. It has no runtime call site, remote destination, persistence, or credential-exfiltration path in the supplied context.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
test
Source
tests/backends.test.js:35

JavaScript analysis reported javascript.xray.unsafe-regex

Expected behavior · high confidence

This is a pattern used to find capitalized names and titles in chat text, which matches the extension's keyword and entity extraction purpose. The supplied evidence shows no external communication, credential access, persistence, or concealed execution.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex in this repository.

Contextual assessment: The flagged expression is a fixed regular expression applied to conversation text during named-entity detection. Its use is synchronous and bounded by the surrounding extraction logic's header-size handling; no attacker-controlled replacement, dynamic evaluation, or security-sensitive data flow is shown. A scanner signal alone does not establish a denial-of-service vulnerability.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
core/keyword-boost.js:719

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · low confidence

This scanner match is a local test endpoint, not evidence of a suspicious online destination. The supplied file uses it only to configure mocked settings.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The candidate corresponds to a localhost llama.cpp endpoint within a test-only mock. No network operation, untrusted input, secret use, or production reachability is shown.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
test
Source
tests/backends.test.js:33

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · medium confidence

The flagged text is a localhost provider address in a configuration list. It supports connecting to a locally running embedding service and does not show an external or concealed destination.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The supplied source shows a fixed default URL using the loopback host for the BananaBread local provider. This is consistent with the extension's documented multi-provider embedding purpose; the evidence shows no request, credential transmission, obfuscation, or remote destination at the flagged line.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
production
Source
core/providers.js:45

JavaScript analysis reported javascript.xray.unsafe-regex

Expected behavior · high confidence

This is a small input-format check for message counts, not code that performs an unsafe operation or handles sensitive data.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex in this repository.

Contextual assessment: The matched expression is fixed, anchored, and limited to an optional comparison operator followed by decimal digits. It is applied to a user-configured display value and has linear, bounded matching behavior, with no evidence of catastrophic backtracking, external communication, persistence, or credential handling.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
ui/chunk-visualizer.js:1624

JavaScript analysis reported javascript.download-to-execution

Expected behavior · low confidence

The supplied excerpt shows a content-vectorizing interface that can fetch user-entered web content, but it does not show downloaded content being executed.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The candidate is based on correlated retrieval and execution-sink signals across a large production-file representation. The supplied source excerpt demonstrates URL fetching UI and user-selected content processing, but does not identify the execution sink, establish data flow from retrieved content into it, or show concealed execution, persistence, credential access, or an attacker-controlled destination.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.download-to-execution
File role
production
Source
ui/content-vectorizer.js:66-1786

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity