TavernKeeper Scan Report

Coneja-Chibi/VectHare

Commit 3339e64 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 49 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex in this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
core/keyword-boost.js:719

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex in this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
ui/chunk-visualizer.js:1624
Deterministic technical evidence (25)
  • Dependency advisory GHSA-qx2v-qp2m-jg93:pkg:d0433ccd51b55fc561da06bf applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v6wh-96g9-6wx3:pkg:c56121eae41b737e771f5dfe applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-23c5-xmqv-rm74:pkg:732c7481baa8e54386dfde00 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5xrq-8626-4rwp:pkg:9050b80cbfdd759d03b3d57f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3v7f-55p6-f55p:pkg:6567e5dee65459862e18aa65 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7r86-cg39-jmmj:pkg:1a39cca405ef708861dee501 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-25h7-pfq9-p65f:pkg:b1d04aa3fb09699f2ce52d11 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:a3638530d49c16954a754a83 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:309438d8c981844c76003c01 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-96hv-2xvq-fx4p:pkg:e7e644a7c4ee2328aaaf410f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-f886-m6hf-6m8v:pkg:16af9086b5e4ae9e3d4dc665 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rf6f-7fwh-wjgh:pkg:b63e05e77a564d495c499726 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4w7w-66w2-5vf9:pkg:b05cf1d2fd08e11489a53642 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-6g55-p6wh-862q:pkg:be20184562ed7ac60b9bb3c5 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:19b149914c26cb2c9c5de439 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:006e2a19c763cc0fc17b9679 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:80dc2988b9d15a40674cea67 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-67mh-4wv8-2f99:pkg:9f437f50cb9a95220530f4b0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:a9b17cadf83e3a5de547592b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-c2c7-rcm5-vvqj:pkg:6159a1838ee53aace6ac3052 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:0546a3b9043a41cf17d6475f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mw96-cpmx-2vgc:pkg:e957faabe27c5ccdac479c31 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3ppc-4f35-3m26:pkg:5b0d86b7147a191050fb118c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fx2h-pf6j-xcff:pkg:4d43116c7f40e099d5763941 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-58qx-3vcg-4xpx:pkg:ba90529056af7ce6d840dc82 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

Contextual expected matches (22)

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

The extension loads a feature using JavaScript's built-in module system, which is safe and normal. There is no hidden downloading or running of external code.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The code uses a standard dynamic import() to asynchronously load a local diagnostics module. This is a normal JavaScript module-loading pattern, not a network retrieval or code execution sink. No eval, fetch, or other dynamic execution primitives are present in the supplied evidence. The scanner correlation is a false positive.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
production
Source
ui/ui-manager.js:1017-3564

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

This file manages the settings UI for VectHare and is written in clear, readable code. The security scanner's alert was a false alarm – there's no hidden or dangerous code here.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The file ui-manager.js is well-structured, readable JavaScript with detailed comments, standard imports, and clear data flow. The JS-X-Ray 'obfuscated-code' signal is a false positive – the code uses large HTML template literals and dynamic property access for UI rendering, which can trigger static analysis obfuscation heuristics, but the actual source is transparent. The file properly handles secrets via the SillyTavern secrets API and has no obfuscated logic.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
ui/ui-manager.js:1

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

The scanner thought this code might be obfuscated, but looking at the actual code, it's clearly written and easy to read. There is no hidden or confusing code here.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The JS-X-Ray scanner flagged obfuscated-code with low confidence, but the provided source is clean, well-commented JavaScript with no obfuscation, minification, or encoded strings. The signal is a false positive likely triggered by template literal syntax or other benign patterns. No actual obfuscation exists in the supplied evidence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
ui/database-browser.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The code contains a default address that points to your own computer (localhost), which is normal for this extension. It's only used if you haven't set a custom address.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The scanner flagged a hardcoded localhost URL for a default vector backend endpoint. This is a standard default connection address for the BananaBread provider, used only when the user does not specify an alternate endpoint. The destination is localhost, not an external host, and matches the extension's documented purpose of connecting to local services. No evidence of malicious intent or data exfiltration.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
backends/standard.js:75

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This is a test file that uses fake settings to check if the extension's memory backends work correctly. The flagged URL and key are just placeholders for testing and have no real security risk.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: A static analysis scanner flagged a URL and mock API key in the unit test file tests/backends.test.js. The file uses vi.mock to create a fake extension_settings object with a localhost URL and a redacted test key for isolated test environments. This is standard testing practice and never executes in production. The mock is part of the Vitest test harness that verifies vector backend implementations. No real credentials or production endpoints are involved, and the code path is not shipped to users.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
test
Source
tests/backends.test.js:19

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The code sets a default address (localhost:8008) for a local service that the extension can connect to. This is normal for tools that need to talk to a program running on your own computer. There is no sign this is harmful.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
diagnostics/production-tests.js:72

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

This file helps debug the VectHare RAG system and is written in clear, readable code. The security scanner's alert was a false alarm – there's no hidden or secret code here.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The file search-debug.js is well-structured, readable JavaScript with comments and no obfuscation. The JS-X-Ray 'obfuscated-code' signal is a false positive likely triggered by large template literal strings and dynamic property access patterns common in UI debugging code. The actual source shows normal developer-authored code with clear data flow limited to local state and DOM manipulation.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
ui/search-debug.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged line is just a default address (localhost) for a local embedding server that runs on your own computer. This is normal and not a security threat.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The flagged line contains a default URL for the BananaBread local embedding server. This server runs on the user's own machine at localhost port 8008, which is standard practice for local services. The scanner flagged a static HTTP URL, but the extension only sends data to this address when the user has configured BananaBread as their provider. No evidence of data exfiltration, credential theft, or malicious network behavior is present. The API key handling in the same block uses extension settings and is not sent to external hosts. This is expected behavior for a local-connection vector embedding provider.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
core/core-vector-api.js:224

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

The scanner thought this code was hidden or scrambled, but the actual code is clean and readable. It's just a normal user interface for viewing memory chunks.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The scanner signal 'obfuscated-code' from JS-X-Ray is a false positive. The supplied source code for file is well-structured, fully commented, and uses standard ES module imports with clear variable naming and logical flow. No obfuscation, minification, or concealed behavior is present. The code implements a legitimate chunk visualizer UI for the VectHare RAG extension.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
ui/chunk-visualizer.js:1

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

This code is not hidden or scrambled. It contains straightforward math for making memories fade over time, exactly as the extension advertises.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The file file is fully readable source code with clear mathematical functions for temporal weighting. No obfuscation is present. The scanner signal is a false positive with low confidence; the code is transparent and matches the project's stated purpose of implementing recency/history bias for RAG context scoring.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
core/temporal-decay.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The code sets a default address to your own computer for a feature that improves search results. This is normal behavior and doesn't send data anywhere unexpected.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The scanner flagged a hardcoded localhost URL on line 349. This URL serves as the default address for the BananaBread reranking endpoint, used only when the user has not configured an alternate endpoint. The destination is localhost, matching the extension's design of connecting to locally running services. No evidence of data exfiltration or external network calls. The secret key handling uses a redacted placeholder but the actual API key is supplied by the user through SillyTavern's secret state management.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
core/chat-vectorization.js:349

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This line is part of the diagnostic tests that make sure your embedding provider works. It takes the server address you configured for BananaBread, or uses a default local address. There is no hidden malicious destination.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The scanner flagged a URL assignment on line 74 of the production-tests.js file. This line is in a helper function that builds provider-specific parameters for the Similharity plugin requests. For the BananaBread provider, it sets an API URL from user settings or defaults to localhost. The generated URL is used only for embedding generation and storage tests that the diagnostics module performs. The URL is not exfiltrated and is only used in requests to the user's configured server. This is expected diagnostic behavior for a RAG extension.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
diagnostics/production-tests.js:74

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

A security scanner thought this file might contain hidden code, but the file is actually clean and readable. The scanner was mistaken.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The static analysis signal 'obfuscated-code' flagged line 1 of collection-loader.js, but the full source is clean, well-commented JavaScript with no obfuscation. The scanner likely matched a false pattern from the file header comments. No actual obfuscated code exists.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
core/collection-loader.js:1

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

The scanner thought the code was hidden or scrambled, but it's actually just a normal comment at the top of the file explaining what the code does.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The scanner classified line 1 as obfuscated code, but the actual source is a standard JavaScript comment block containing the file header description. There is no obfuscation present. The signal is a false positive from the abstract syntax tree analysis matching a pattern unrelated to the actual code content. The code is completely readable and transparent.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
backends/standard.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

A security scanner flagged a line in the diagnostics report as suspicious, but it is just text that gets copied to the clipboard. It does not involve any external link or dangerous action.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The shady-link signal at line 3232 matches a template literal string used in a diagnostics report UI. The matched literal is part of a status display and is not a URL, network endpoint, or any external reference. The scanner pattern triggered on static text that is harmless in context.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
ui/ui-manager.js:3232

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

This file contains normal, readable code with comments and standard imports. It is not obfuscated.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The obfuscated-code signal (line 1) is a false positive. The file is structured JavaScript with clear imports, documented functions, and no minification or obfuscation. The scanner likely triggered on the file header comment or module structure.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
core/chat-vectorization.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This diagnostic tool checks if your BananaBread embedding server is reachable. The flagged line just sets the server address, which you can configure or defaults to your own computer. It is not a shady link—it is a normal connectivity check.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The scanner flagged a URL assignment on line 39 of the infrastructure diagnostics file. That line constructs the API URL for the BananaBread provider by choosing between a user-configured alternative endpoint and a default localhost address. This URL is used only to test connectivity to the BananaBread embedding service, a legitimate provider supported by the extension. No evidence shows the URL points to an external malicious host or that any data is exfiltrated. The behavior is proportional to the project's stated purpose of providing multi-backend RAG diagnostics.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
diagnostics/infrastructure.js:39

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

The scanner worried that the extension might download code and run it, but the code only fetches a simple health check and never executes anything it downloads. The extension is just checking if a plugin is available.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The scanner flagged a correlation between a network retrieval (fetch to /api/plugins/similharity/health) and a code execution sink, but the supplied source contains no dynamic code execution from network responses. The fetch result is only used to set a boolean (response.ok) for plugin availability. The file uses standard DOM manipulation (jQuery append) for UI construction from local template literals, not from network data. No eval, Function, innerHTML injection from network, or similar sink exists in the evidence. The signal is a false positive.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
production
Source
ui/database-browser.js:96-444

JavaScript analysis reported javascript.xray.encoded-literal

Expected behavior · high confidence

The test code uses a normal word like 'abc123' to check if collection IDs are parsed correctly. There's no hidden or encoded data.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.encoded-literal in this repository.

Contextual assessment: The scanner signal 'encoded-literal' at line 680 of file matches an assertion string literal 'abc123' in a test that parses collection IDs. This is a plain string, not encoded or obfuscated. The scanner likely produced a false positive on a simple test assertion.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.encoded-literal
File role
test
Source
tests/backends.test.js:680

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · low confidence

This file is a normal math library for comparing vectors—it's not hidden or scrambled. The scanner mistakenly thought it was obfuscated.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code in this repository.

Contextual assessment: The file 'vector-distance.js' contains clear, well-documented mathematical algorithms (Jaccard, Hamming, Cosine distances) with no obfuscation or hidden code. The scanner's obfuscated-code signal is a false positive, likely triggered by the high density of numeric operations or the presence of many function definitions. No minification, encoding, or concealment is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
utils/vector-distance.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This is just a default setting for connecting to a local server on your own machine. It's not a security risk.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The defaultUrl field at line 45 defines the default URL for BananaBread, a local embedding server. Using localhost is standard practice for services that run on the user's own machine. The scanner flagged a static HTTP URL, but the extension only uses this URL when the user configures BananaBread as their provider. No evidence of malicious intent, data exfiltration, or unauthorized network access is present. This is a legitimate configuration default.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
core/providers.js:45

JavaScript analysis reported javascript.download-to-execution

Expected behavior · low confidence

This file lets users choose content to vectorize, including fetching a webpage by URL. That's a normal feature for a RAG tool. The scanner thought it might also run code from fetched content, but the code shown doesn't do that. No danger found.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The file file is a UI modal for selecting and configuring content to vectorize. It includes a URL input to fetch external content, which is a visible feature consistent with the project's stated RAG purpose. The provided source code does not contain any dynamic code execution sink such as eval(), new Function(), or similar. The scanner's correlation between network retrieval and a code execution sink is not supported by the evidence; no such sink is present in the supplied snippets. The risk is not demonstrated.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
production
Source
ui/content-vectorizer.js:66-1786

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity