What this review found
Dependency advisory GHSA-5xrq-8626-4rwp applies
Material concern · low confidence
A scanner found a critical advisory, but the supplied evidence does not identify the package, version, or whether users can reach the affected code.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.
Contextual assessment: The advisory match is in a production lockfile, but package identity, installed version, advisory condition, runtime reachability, and attacker-controlled input are omitted. A critical scanner label alone cannot establish immediate danger.
Impact: high · Exploitability: plausible
Developer action: Provide the matched package and installed version, then assess whether production runtime reaches the vulnerable code before upgrading or documenting the finding.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-5xrq-8626-4rwp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-v6wh-96g9-6wx3 applies
Material concern · low confidence
A scanner found a medium-severity dependency advisory, but there is not enough detail to tell whether the extension is affected during normal use.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.
Contextual assessment: The evidence records an advisory match but removes package details and provides no version, reachability, input-flow, or impact information. The lockfile is production-role, yet the visible root entries are test-only, so dependency placement is also unresolved.
Impact: medium · Exploitability: plausible
Developer action: Provide the matched package and installed version, then verify runtime reachability and upgrade if the advisory affects shipped execution.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-v6wh-96g9-6wx3
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-25h7-pfq9-p65f applies
Material concern · low confidence
A high-severity dependency warning was reported, but the evidence does not show what component is involved or whether normal users can trigger it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-25h7-pfq9-p65f to a dependency declared by this repository.
Contextual assessment: Only the advisory identifier and scanner classification are supplied. No package/version, vulnerable range, runtime reachability, attacker-controlled input, or concrete harm is available.
Impact: high · Exploitability: plausible
Developer action: Identify the package and installed version and determine whether the vulnerable path is shipped and reachable before applying a targeted upgrade.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-25h7-pfq9-p65f
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-4w7w-66w2-5vf9 applies
Material concern · low confidence
A medium-severity advisory was detected, but the supplied report omits the information needed to decide whether users are exposed.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.
Contextual assessment: The match lacks package identity, installed version, vulnerable behavior, runtime reachability, and attacker-input analysis. The result is therefore a material unresolved dependency issue, not a confirmed exploitable vulnerability.
Impact: medium · Exploitability: plausible
Developer action: Identify the affected package and version and assess whether it is runtime-reachable in the shipped extension.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4w7w-66w2-5vf9
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-23c5-xmqv-rm74 applies
Material concern · low confidence
A high-severity dependency warning exists, but the evidence does not establish that the extension actually uses the vulnerable behavior.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.
Contextual assessment: The scanner output omits package/version and all runtime data-flow details. Severity and confidence describe the advisory match, not exploitability in this project.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version and validate production reachability and exploit conditions before upgrading or documenting an exception.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-23c5-xmqv-rm74
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Material concern · low confidence
A high-severity dependency issue was flagged, but the supplied evidence cannot show how a user could encounter it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: There is only an advisory identifier and scanner classification. Package identity, version, vulnerable range, runtime reachability, attacker control, and concrete impact are unavailable.
Impact: high · Exploitability: plausible
Developer action: Provide package/version details and verify whether the advisory affects runtime code included and reachable by the extension.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-28wg-ghj8-5hjv applies
Material concern · low confidence
A high-severity advisory was reported, but the report lacks enough detail to determine whether it affects real extension use.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-28wg-ghj8-5hjv to a dependency declared by this repository.
Contextual assessment: The supplied evidence does not include package/version, advisory semantics, runtime reachability, attacker-controlled input, or resulting harm. It supports follow-up, not a confirmed immediate exploit.
Impact: high · Exploitability: plausible
Developer action: Identify the dependency and installed version and assess whether the vulnerable code is reachable in production execution.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-28wg-ghj8-5hjv
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-7r86-cg39-jmmj applies
Material concern · low confidence
A high-severity dependency warning was found, but the supplied material does not show whether users are exposed during ordinary operation.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.
Contextual assessment: Only the advisory identifier and scanner severity are available. The package, installed version, vulnerable behavior, reachability, and attacker-input path are absent.
Impact: high · Exploitability: plausible
Developer action: Identify the affected package and installed version and test whether normal production flows reach the vulnerable code.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-7r86-cg39-jmmj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Material concern · low confidence
A scanner found a known issue in a dependency, but the supplied evidence does not identify the package or show whether the extension uses the affected code.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: The advisory match is high-confidence scanner evidence, but package identity, installed version, vulnerability mechanism, and runtime reachability were removed. Impact and exploitability therefore cannot be established beyond a conditional dependency risk.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-96hv-2xvq-fx4p applies
Material concern · low confidence
A scanner found a high-severity dependency issue, but the supplied evidence does not show which package is affected or whether users can reach the vulnerable behavior.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-96hv-2xvq-fx4p to a dependency declared by this repository.
Contextual assessment: The scanner reports a high-severity advisory for a declared dependency, but package details, version range, reachability, attacker-controlled input, and concrete impact are unavailable.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-96hv-2xvq-fx4p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3ppc-4f35-3m26 applies
Material concern · low confidence
A scanner found a high-severity dependency issue, but the supplied evidence does not establish whether this affects normal extension operation.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.
Contextual assessment: The advisory match is not enough to determine practical exposure because the affected package, installed version, vulnerable path, and attacker input path are omitted.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3ppc-4f35-3m26
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mh99-v99m-4gvg applies
Material concern · low confidence
A scanner reported a high-severity issue in a dependency, but there is not enough information to tell whether it creates a usable attack against this extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: Package identity, version, advisory behavior, runtime reachability, and attacker control are unavailable, so this remains a conditional material dependency concern rather than an immediate-danger finding.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-58qx-3vcg-4xpx applies
Material concern · low confidence
A scanner found a known dependency issue, but the evidence does not reveal whether the affected functionality is used by the extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-58qx-3vcg-4xpx to a dependency declared by this repository.
Contextual assessment: The scanner match lacks the dependency name, installed version, vulnerability details, and runtime data flow needed for contextual severity assessment.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-58qx-3vcg-4xpx
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Material concern · low confidence
A scanner reported a high-severity dependency problem, but the supplied material cannot show whether it can harm users of this extension.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: The advisory severity is not sufficient for an immediate-danger conclusion; affected package, version, reachability, input control, and concrete harm are missing.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-2v37-7h3g-55p8 applies
Material concern · low confidence
A scanner found a high-severity issue in a dependency, but the evidence does not identify an exposed feature or attack path.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2v37-7h3g-55p8 to a dependency declared by this repository.
Contextual assessment: The supplied record omits the package, installed version, affected code path, runtime use, and attacker-controlled input, preventing a more specific assessment.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2v37-7h3g-55p8
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Material concern · low confidence
A scanner reported a high-severity dependency issue, but the supplied evidence does not show whether normal users can trigger it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: The match is high-confidence at scanner level, while package identity, installed version, vulnerability conditions, runtime reachability, and impact remain unspecified.
Impact: medium · Exploitability: plausible
Developer action: Identify the matched package and installed version, confirm runtime reachability, and update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- package-lock.json
Minor cautions
JavaScript analysis reported javascript.xray.obfuscated-code
Minor caution · low confidence
The scanner noticed a possible obfuscated-code pattern, but the supplied material does not show what was matched or indicate harmful behavior. Obfuscation can make future review harder, so the affected code should be explained or simplified.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The only supplied finding is a low-confidence static obfuscation signal. The provided source excerpt shows ordinary module imports and UI-manager documentation, while matched literals were not retained. There is no evidence here of concealed execution, credential theft, unauthorized persistence, or external exfiltration. Because the flagged representation and relevant code path are unavailable, intent and exact behavior cannot be fully assessed.
Impact: low · Exploitability: unlikely
Developer action: Provide the flagged JavaScript representation or scanner details identifying the matched construct, and document or remove any intentional obfuscation.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- production
- Source
- ui/ui-manager.js:1
JavaScript analysis reported javascript.xray.shady-link
Minor caution · medium confidence
The extension sends provider connection details and, when configured, an API key to the local plugin service so it can test or generate embeddings. That fits its vector-search purpose, but storing the key in extension settings and allowing a user-selected endpoint deserves extra protection.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The flagged code constructs provider-specific request parameters. For the BananaBread provider it selects either a user-configured alternate endpoint or a localhost default and includes the configured provider API key in the request body. The evidence shows intentional provider integration and no evidence of an unrelated destination, concealment, or exfiltration. The use of a configurable endpoint and plaintext HTTP default creates transport and credential-handling concerns, but does not establish malicious behavior from the supplied context alone.
Impact: medium · Exploitability: plausible
Developer action: Document the endpoint and credential handling clearly; prefer the host application's secret storage where available, and use secure transport for configurable remote endpoints.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- diagnostics/production-tests.js:72
JavaScript analysis reported javascript.xray.obfuscated-code
Minor caution · low confidence
The scanner noticed a possible pattern associated with hard-to-read JavaScript, but the supplied evidence does not show what caused it or whether it hides harmful behavior.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The candidate is based on a low-confidence obfuscation signal, while the supplied source context contains only the beginning of a production debug-modal file and no retained matched literals or complete data-flow evidence. The visible comments describe diagnostics for a RAG search pipeline, which is consistent with the file's stated role, but the available evidence cannot assess the remainder of the 74 KB artifact or determine whether any obfuscation is intentional and benign. This is insufficient to establish malicious execution, credential access, exfiltration, or concealed persistence; the incomplete visibility is a review limitation rather than evidence of safety.
Impact: low · Exploitability: unlikely
Developer action: Provide the complete file contents or the scanner's retained matched regions for review, and document any intentional generated or minified sections.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- production
- Source
- ui/search-debug.js:1
Dependency advisory GHSA-6g55-p6wh-862q applies
Minor caution · low confidence
A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-6g55-p6wh-862q to a dependency declared by this repository.
Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-6g55-p6wh-862q
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-67mh-4wv8-2f99 applies
Minor caution · low confidence
A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-67mh-4wv8-2f99 to a dependency declared by this repository.
Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-67mh-4wv8-2f99
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-rf6f-7fwh-wjgh applies
Minor caution · low confidence
A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh to a dependency declared by this repository.
Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rf6f-7fwh-wjgh
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · low confidence
A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · low confidence
A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-mw96-cpmx-2vgc applies
Minor caution · low confidence
A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mw96-cpmx-2vgc to a dependency declared by this repository.
Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mw96-cpmx-2vgc
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · low confidence
A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-qx2v-qp2m-jg93 applies
Minor caution · low confidence
A scanner found a reported issue in a dependency, but the supplied record does not identify the package, version, or whether production code uses it.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-qx2v-qp2m-jg93 to a dependency declared by this repository.
Contextual assessment: The evidence only establishes an advisory match in the lockfile. Package identity, affected-version range, dependency reachability, attacker-controlled input, and concrete impact are unavailable; the visible root entries indicate test tooling, which may not ship or execute in production.
Impact: low · Exploitability: unlikely
Developer action: Identify the affected package and installed version, confirm runtime reachability, then update or remove it if applicable.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-qx2v-qp2m-jg93
- File role
- production
- Source
- package-lock.json
Dependency advisory GHSA-fx2h-pf6j-xcff applies
Minor caution · low confidence
A scanner found a known issue in one dependency, but the supplied evidence does not identify the package or show that the extension uses the vulnerable code. The visible lockfile section lists only testing tools as direct development dependencies.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.
Contextual assessment: The advisory match is metadata indicating a declared dependency, but the package identity, installed version, vulnerable component, runtime reachability, attacker-controlled input, and concrete impact are omitted. The shown root manifest contains only development dependencies, so production exposure cannot be established from the supplied context. This warrants remediation and dependency verification, not an immediate-danger classification.
Impact: low · Exploitability: unlikely
Developer action: Identify the exact affected package and installed version, determine whether it is production-reachable or only a development/test dependency, then update or replace it if the advisory applies.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fx2h-pf6j-xcff
- File role
- production
- Source
- package-lock.json
Expected scanner matches (26)
JavaScript analysis reported javascript.download-to-execution
Expected behavior · low confidence
The scanner found network-related and dynamic-execution patterns somewhere in a large user-interface file, but the supplied excerpt only shows diagnostic dialogs, console capture, report generation, and user-triggered fixes. It does not show downloaded content being executed.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: Review the omitted portions of the module and its imported diagnostics code to confirm whether any retrieved data reaches an executable sink; separate diagnostic UI rendering from actual execution.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.download-to-execution
- File role
- production
- Source
- ui/ui-manager.js:1017-3564
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · low confidence
The available evidence only reports a low-confidence scanner signal for obfuscation. It does not show hidden behavior, data theft, or harmful execution.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The supplied production source is text evidence, but the candidate contains no retained matched literals or code-flow details. Imports and the stated database-browser purpose are consistent with an extension managing vector collections; the obfuscation signal alone does not establish concealment or malicious behavior.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- production
- Source
- ui/database-browser.js:1
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · low confidence
The scanner flagged a network-related pattern, but the supplied line is only a test mock for a local service address. It does not show an external connection or secret transmission.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The candidate points to a test fixture configuring a local Ollama endpoint. The evidence contains no request execution, attacker-controlled destination, credential flow, or exfiltration behavior.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- test
- Source
- tests/backends.test.js:34
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
The flagged fixed address is a local embedding-service fallback, which fits the extension’s stated vector-backend purpose and does not show data being sent to an unrelated destination.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The observed value is a localhost URL selected only for the bananabread provider when no alternate endpoint is configured. It is paired with provider-specific API parameters and is not evidence of a concealed external connection.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- backends/standard.js:75
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · low confidence
This is a test-only local API address used to imitate the extension's configured service. The supplied evidence does not show data leaving the user's machine.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The flagged value is a localhost API URL in mocked extension settings. It is test configuration rather than production network behavior, and no external destination or sensitive-data transfer is evidenced.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- test
- Source
- tests/backends.test.js:19
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
The flagged line selects a local service address for the configured embedding backend. This matches the extension’s purpose of supporting local model servers and does not show hidden communication.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The fixed address is used only as the default API endpoint for the explicitly selected Bananabread provider; an alternate configured endpoint can be used. The supplied evidence shows no concealment, unrelated destination, credential exfiltration, or execution behavior.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- core/core-vector-api.js:224
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · low confidence
The available evidence only says an automated tool noticed a possible obfuscation pattern. It does not show what was hidden or that the extension performs harmful actions.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The candidate is a low-confidence static obfuscation signal with matched literals withheld. The supplied source context shows a production visualizer module with ordinary imports related to chunk metadata, vector operations, scenes, hashing, and host integration, but it does not establish concealed execution, credential access, exfiltration, persistence, or malicious update behavior. Because the complete file behavior and matched signal are not available, this is not evidence of malicious behavior by itself; targeted review is still appropriate if obfuscation remains present in the artifact.
Impact: none · Exploitability: unlikely
Developer action: Provide the scanner-matched literals or a readable, non-transformed representation and review any dynamic execution, network, storage, and credential-handling paths.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- production
- Source
- ui/chunk-visualizer.js:1
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · low confidence
The supplied lines show ordinary temporal-memory calculations, but they do not include the code that caused the scanner signal. There is no evidence here of harmful behavior.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The candidate is a low-confidence static obfuscation signal. The available source slice contains imports, comments, and simple mathematical functions consistent with the stated temporal-decay feature, with no visible concealment, external destination, credential handling, persistence, or execution. Because only lines 1–41 are supplied for an 18,358-byte production file, the flagged representation and remaining behavior cannot be fully assessed; this is an assessment of the candidate, not proof of the artifact's overall safety.
Impact: none · Exploitability: unlikely
Developer action: Provide the complete file or a sufficiently broad source slice so the flagged representation and any related data flows can be inspected.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- production
- Source
- core/temporal-decay.js:1
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
The flagged value selects either the configured embedding service or a local default. This is part of sending text for vectorization, which matches the extension’s retrieval purpose; the supplied code does not show a hidden destination or concealed behavior.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The code derives the embedding endpoint from a user-configurable setting, otherwise uses a local service address, then posts cleaned input text to an embeddings API. An optional configured API key is placed in the request authorization header. The scanner signal alone does not establish malicious networking, and the visible data flow is consistent with the documented embedding functionality.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- core/core-vector-api.js:447
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
When BananaBread is selected, the extension checks the configured server for available models. It may include the API key that the user entered so the server can authenticate the request. This matches the documented model-provider connection purpose.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The code constructs a server URL from user-controlled provider settings, defaults to a local BananaBread endpoint, and performs a GET request to its models endpoint. A configured provider API key is placed in an Authorization header for that same configured endpoint. The supplied evidence shows no unrelated destination, concealment, persistence, or exfiltration behavior; the fixed signal is consistent with an endpoint URL used by the provider health check.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- diagnostics/infrastructure.js:939
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · medium confidence
The flagged code sends chat text and a configured authentication key to a reranking service so the extension can improve search results. That matches the advertised RAG and reranking features. The supplied evidence does not show a hidden third-party destination, although the alternate address and key handling should be made explicit to users.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The function selects either a user-configured alternate endpoint or a localhost service, then posts the query, retrieved document text, and an API-key field through the host plugin route for reranking. This is proportionate to the documented optional reranking/backend functionality. The evidence does not establish covert exfiltration or malicious behavior, but it does not reveal the key's source or validate alternate-endpoint restrictions; those are disclosure and hardening concerns rather than demonstrated compromise.
Impact: low · Exploitability: unlikely
Developer action: Document the reranking endpoint and API-key handling clearly in the settings and README; ensure the key is sourced from user-configured state and is sent only to the intended local or explicitly configured backend.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- core/chat-vectorization.js:349
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
This code prepares connection details for a locally configured model service. The detected link-like value is a local endpoint, and the key is included for the plugin request rather than sent to an unrelated destination.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The flagged value is an endpoint constructed for the BananaBread provider, defaulting to a local service address or a user-selected alternate endpoint. The same function adds the configured provider key to the request parameters. The supplied context shows provider-specific request preparation consistent with the extension's stated vector-embedding purpose, with no evidence of a fixed external destination, concealment, or unrelated exfiltration.
Impact: none · Exploitability: unlikely
Developer action: Review whether the BananaBread endpoint and API key must be sent in the request body; if required, document this clearly and prefer the host application's secret-handling facilities where available.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- diagnostics/production-tests.js:74
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · low confidence
The available evidence only says that an automated scanner noticed a possible obfuscation pattern. It does not show what was matched or demonstrate hidden, harmful behavior.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The candidate is a low-confidence static obfuscation signal with matched literals omitted. The supplied source context contains only imports, comments, and exports, not the flagged representation or an observable suspicious data flow. Obfuscation alone is insufficient to infer malicious behavior or a vulnerability in this extension's collection-management purpose.
Impact: none · Exploitability: unlikely
Developer action: Provide the complete transformed JavaScript or the scanner's retained match details and surrounding source so the signal can be assessed.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- production
- Source
- core/collection-loader.js:1
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · low confidence
The supplied material does not show meaningful code hiding or suspicious execution. The scanner result alone is too weak to establish a security problem.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: Only a low-confidence obfuscation signal is supplied, without matched content. The available source excerpt is readable, documented provider-selection code, and does not demonstrate concealed behavior, credential theft, or unrelated persistence.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- production
- Source
- backends/standard.js:1
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · low confidence
The scanner detected a link-like signal, but the actual matched value was withheld. The visible code displays configured provider or database endpoints in a report and does not show an unexplained connection.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The evidence identifies only a static scanner signal and explicitly omits the matched literal. Nearby supplied logic obtains endpoint values from extension settings for inclusion in a diagnostics report; it does not demonstrate a hidden destination, automatic transmission, credential collection, or execution. Because the literal and complete surrounding code are unavailable, intent and destination cannot be confirmed, but the candidate alone does not support a security finding.
Impact: none · Exploitability: unlikely
Developer action: Inspect the omitted literal and surrounding logic to identify the matched link and verify that it is an intentional provider, documentation, or user-configured endpoint rather than an undisclosed destination.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- ui/ui-manager.js:3232
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · low confidence
The scanner found a weak signal that some JavaScript may look unusual, but the supplied evidence does not show hidden behavior, stolen data, or a harmful destination. This file is the extension's main vectorization and retrieval logic, where complex generated or bundled-looking code can occur.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The candidate is based only on a low-confidence obfuscation heuristic. Supplied source context shows ordinary ES module imports for chat retrieval, vector storage, embedding backends, filtering, diagnostics, and request headers, all consistent with the stated RAG purpose. No obfuscated payload, concealed execution, credential exfiltration, persistence mechanism, or external destination is evidenced. The assessment is limited because the candidate metadata does not retain the matched literals or precise behavior, and the provided source excerpt is incomplete relative to the full file supplied by hash and size metadata only for scanner matching.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- production
- Source
- core/chat-vectorization.js:1
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
The flagged link-like value is a local service address used for a supported provider connection, not a concealed outside destination.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The candidate is a fixed loopback HTTP endpoint selected only when the configured provider is BananaBread and no alternate endpoint is enabled. The surrounding code assembles provider parameters for plugin requests; the supplied evidence shows no external destination, credential transmission beyond that provider request, obfuscation, or covert execution.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- diagnostics/infrastructure.js:39
JavaScript analysis reported javascript.download-to-execution
Expected behavior · low confidence
The supplied excerpt shows ordinary browser UI and API activity for a database browser, but it does not show downloaded content being executed.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.
Contextual assessment: The candidate is based on a broad correlation between network retrieval and a possible execution sink within a large JavaScript representation. The supplied context shows a health check using fetch and extensive UI, import, export, and collection-management logic. It does not identify a specific retrieved response flowing into dynamic evaluation, command execution, or another executable sink. Because the excerpt is truncated before the candidate range ends, the conclusion is limited to the supplied evidence and does not establish malicious or vulnerable behavior.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.download-to-execution
- File role
- production
- Source
- ui/database-browser.js:96-444
JavaScript analysis reported javascript.xray.encoded-literal
Expected behavior · high confidence
The flagged text is a normal test value used to check how collection identifiers are parsed. It does not perform hidden actions or send data.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.encoded-literal in this repository.
Contextual assessment: The candidate points to a fixed identifier string in a backend unit test. The surrounding test verifies parsing of a documented collection-ID format; no execution, decoding, persistence, or external data flow is shown at the flagged location.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.encoded-literal
- File role
- test
- Source
- tests/backends.test.js:680
JavaScript analysis reported javascript.xray.obfuscated-code
Expected behavior · low confidence
The supplied portion is a documented mathematical utility for comparing vectors, which fits the extension’s retrieval purpose. The scanner provided only a low-confidence obfuscation signal and retained no matching values; this evidence does not show hidden behavior, data collection, or secret handling.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.
Contextual assessment: The available source excerpt shows ordinary, readable vector-distance implementation with no dynamic execution, networking, persistence, credential access, or encoded payload. The candidate is based only on low-confidence scanner metadata, so it does not substantiate malicious obfuscation or a vulnerability in this production utility file.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.obfuscated-code
- File role
- production
- Source
- utils/vector-distance.js:1
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · low confidence
The flagged address is another local development endpoint in a test mock. Nothing supplied indicates that the extension contacts it unexpectedly or sends private information.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The evidence identifies a mocked local vLLM server URL. It has no runtime call site, remote destination, persistence, or credential-exfiltration path in the supplied context.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- test
- Source
- tests/backends.test.js:35
JavaScript analysis reported javascript.xray.unsafe-regex
Expected behavior · high confidence
This is a pattern used to find capitalized names and titles in chat text, which matches the extension's keyword and entity extraction purpose. The supplied evidence shows no external communication, credential access, persistence, or concealed execution.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex in this repository.
Contextual assessment: The flagged expression is a fixed regular expression applied to conversation text during named-entity detection. Its use is synchronous and bounded by the surrounding extraction logic's header-size handling; no attacker-controlled replacement, dynamic evaluation, or security-sensitive data flow is shown. A scanner signal alone does not establish a denial-of-service vulnerability.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- core/keyword-boost.js:719
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · low confidence
This scanner match is a local test endpoint, not evidence of a suspicious online destination. The supplied file uses it only to configure mocked settings.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The candidate corresponds to a localhost llama.cpp endpoint within a test-only mock. No network operation, untrusted input, secret use, or production reachability is shown.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- test
- Source
- tests/backends.test.js:33
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · medium confidence
The flagged text is a localhost provider address in a configuration list. It supports connecting to a locally running embedding service and does not show an external or concealed destination.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.
Contextual assessment: The supplied source shows a fixed default URL using the loopback host for the BananaBread local provider. This is consistent with the extension's documented multi-provider embedding purpose; the evidence shows no request, credential transmission, obfuscation, or remote destination at the flagged line.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.shady-link
- File role
- production
- Source
- core/providers.js:45
JavaScript analysis reported javascript.xray.unsafe-regex
Expected behavior · high confidence
This is a small input-format check for message counts, not code that performs an unsafe operation or handles sensitive data.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex in this repository.
Contextual assessment: The matched expression is fixed, anchored, and limited to an optional comparison operator followed by decimal digits. It is applied to a user-configured display value and has linear, bounded matching behavior, with no evidence of catastrophic backtracking, external communication, persistence, or credential handling.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- ui/chunk-visualizer.js:1624
JavaScript analysis reported javascript.download-to-execution
Expected behavior · low confidence
The supplied excerpt shows a content-vectorizing interface that can fetch user-entered web content, but it does not show downloaded content being executed.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.
Contextual assessment: The candidate is based on correlated retrieval and execution-sink signals across a large production-file representation. The supplied source excerpt demonstrates URL fetching UI and user-selected content processing, but does not identify the execution sink, establish data flow from retrieved content into it, or show concealed execution, persistence, credential access, or an attacker-controlled destination.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
- Rule
- javascript.download-to-execution
- File role
- production
- Source
- ui/content-vectorizer.js:66-1786