TavernKeeper Scan Report

NeoTavern/NeoTavern-Frontend

Commit 86ca333 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 49 low

What this review found

No material or immediate-danger item was identified.

Deterministic technical evidence (37)
  • Dependency advisory GHSA-v2wj-q39q-566r:pkg:2da03775dcf45324bfa61d36 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:1c043fdb9ddfee4f4331dbb0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:387ff1385f57b2b03c5ec3e6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-c2j3-45gr-mqc4:pkg:3a617860720e33c3832a83a7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-xvcm-6775-5m9r:pkg:a5026003cd504f00b4f9b2ba applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:3f058ee2b68aac4f6bcbbf9e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: vite.config.ts:79

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:36b5ec528a6a84376d2fa8cc applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:678d4d4a8016db80660c8069 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/build-profile.js:4

  • Dependency advisory GHSA-8xcm-r25x-g524:pkg:9efcb22ccad71d16e9fbb4db applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4cwx-7wf7-3272:pkg:1176429e737cfabdf766cdff applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-m8rv-5g2x-5cg5:pkg:effd824192445928106e41b7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:f395337a0cb5249680cc1cad applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v6wh-96g9-6wx3:pkg:ac373679d1ec0446c126c2b6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fx2h-pf6j-xcff:pkg:dd82781926efc7ade22030d3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-pm4m-ph32-ghv5:pkg:9fbe9520ff824acfe7c4ed6a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8r6m-32jq-jx6q:pkg:4103fd8f223da7e70be01de8 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/build-profile.js:8-12

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:3a2d891c083fd08457b3fe41 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:32565e5915130b51271b4195 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: vite.config.ts:32

  • Dependency advisory GHSA-55q2-fjhq-7xh7:pkg:2fd628b415ad04f802a2d1cc applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-p9ff-h696-f583:pkg:4fdb809d17c4d326174c35f0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v3r7-h72x-cjcm:pkg:2f99006f4e2ddba635fa3089 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v56q-mh7h-f735:pkg:95da09a06d8bd82445831b2f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:33bd75a43666b34e8d957c42 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:d681b9f3617b82bd6b835445 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: vite.config.ts:3

  • Dependency advisory GHSA-4c8g-83qw-93j6:pkg:a90c096b0a189e0f49499767 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4w7w-66w2-5vf9:pkg:cdcea1ddcbe6ed9555aaec70 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-jr45-8vmc-qm54:pkg:ef6cbe09bba3516afec0221f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

Contextual expected matches (11)

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The flagged line is just CSS styling code for a layout class. It has nothing to do with persistence or startup behavior.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification. The match applies to this repository.

Contextual assessment: The scanner flagged line 473 in a Vue SFC, but the supplied source context shows line 473 is inside a scoped SCSS style block defining the `.profile-actions` CSS class with display, gap, and flex-wrap properties. There is no startup persistence modification, no executable logic, no data flow, and no runtime behavior at this location. This is a scanner false positive on CSS declarations.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/model-randomizer/SettingsPanel.vue:473

JavaScript analysis reported javascript.xray.unsafe-command

Expected behavior · high confidence

The code runs a fixed git command to check the current version. The command text never changes and contains no user input, so there is no way for an attacker to alter what it does.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-command. The match applies to this repository.

Contextual assessment: The flagged line executes a fixed, hardcoded git command ('git rev-parse HEAD') with no interpolated or user-controlled input. The launcher's stated purpose is to manage a SillyTavern backend, and this call retrieves the current commit hash for build-change detection. No untrusted input reaches the command string, so there is no injection path.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-command
File role
production
Source
launcher.js:162

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The flagged line is CSS styling for a profile management section. It does not modify any startup behavior.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification. The match applies to this repository.

Contextual assessment: The scanner flagged line 458, which is inside the scoped SCSS style block defining the `.profile-management` CSS class with display, flex-direction, and gap properties. No executable code, no persistence mechanism, no data flow. Scanner false positive on CSS.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/model-randomizer/SettingsPanel.vue:458

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The flagged line is CSS styling for profile content layout. It has no connection to startup persistence.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification. The match applies to this repository.

Contextual assessment: The scanner flagged line 479, which is inside the scoped SCSS style block defining the `.profile-content` CSS class with display, flex-direction, gap, padding, background, and border-radius properties. No executable code or persistence behavior. Scanner false positive on CSS declarations.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/model-randomizer/SettingsPanel.vue:479

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The launcher contains links to public GitHub repositories so it can download the software it needs. These are normal, fixed addresses that match what the project says it does.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The signal corresponds to hardcoded GitHub repository URLs used by the launcher to clone the SillyTavern backend and the NeoTavern server plugin. These are well-known public repositories and match the project's stated all-in-one launcher purpose. No dynamic or attacker-controlled URL is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
launcher.js:31

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The flagged code reads the project's version number from the build environment and puts it in a comment at the top of generated type files. This is standard build tooling and involves no sensitive information.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The JS-X-Ray scanner flagged line 18 for a serialize-environment signal triggered by `process.env.npm_package_version`. This file is a Vite build configuration (`file`) used only during the type-definition build step. The accessed environment variable is `npm_package_version`, a standard non-sensitive build metadata value automatically set by npm. It is interpolated into a comment header in generated `.d.ts` type definition files. There is no credential access, no network exfiltration, no runtime exposure, and no sensitive data flow. This is a build-time tool reading package version metadata, which is entirely benign and expected for a build configuration file.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
vite.config.types.ts:18

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The launcher lets you override settings using environment variables, which is a normal way to configure a local app. It only reads specific variables it needs and does not send them anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The flagged region reads NEO_* environment variables locally to override configuration values such as ports, host, and authentication settings. This is a standard configuration pattern for a local launcher process. The variables are read only and assigned to internal config fields; there is no serialization, transmission, or exfiltration of the full process environment. The basic-auth password value is redacted in the supplied evidence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
launcher.js:110

Gitleaks reported generic-api-key

Expected behavior · high confidence

The file defines which settings screen to show for each AI provider. It references a key name, not an actual secret, so no credential is exposed.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key. The match applies to this repository.

Contextual assessment: The matched line is a UI configuration definition that references SECRET_KEYS.AI21, an enum or constant identifier used to associate a key-manager widget with the AI21 provider. No actual API key value is present in the source; the file defines which settings widgets to render for each AI provider. The gitleaks pattern matched the constant reference, not a real credential. This matches the project's stated purpose of managing API connections for multiple model providers.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
production
Source
src/api-connection-definition.ts:169

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The flagged line is CSS styling for a profile row in an NPC management panel. The component itself manages NPC character data for a game tool extension, which is its stated purpose. There is no malicious persistence behavior.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification. The match applies to this repository.

Contextual assessment: The scanner flagged line 304 with a startup persistence modification rule. The supplied source context shows line 304 is inside the scoped SCSS style block of a Vue SFC, defining the `.profile-row` CSS class with display, gap, and font-size properties. The component's script section (lines 1-118) contains standard Vue composition API logic for adding, editing, and removing NPCs in a mythic agents extension. The `updateLatestExtra` calls persist scene character data to the extension state, which is expected behavior for a settings panel managing NPC lists. There is no startup hook, no concealed persistence, and no malicious data flow. The scanner match is on CSS declarations, not executable persistence logic.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/mythic-agents/components/NpcTab.vue:304

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The flagged line is just a CSS style rule for a UI section. The component saves user preferences through the app's normal settings system, which is expected behavior for a settings popup.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification. The match applies to this repository.

Contextual assessment: The flagged line is a CSS class selector (.profile-section) inside a scoped style block. The component's script uses standard Vue lifecycle hooks (onMounted, watch) to load and save extension settings and chat metadata through the provided extension API. Saving a connection-profile preference and active-tab state is expected behavior for a settings popup and does not constitute startup or system persistence modification.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/chat-memory/MemoryPopup.vue:109

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The flagged line is CSS styling for profile control buttons. It does not modify any startup behavior.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification. The match applies to this repository.

Contextual assessment: The scanner flagged line 464, which is inside the scoped SCSS style block defining the `.profile-controls` CSS class with display, gap, and a nested `.profile-select` rule. No executable code, no persistence mechanism, no data flow. Scanner false positive on CSS.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
src/extensions/built-in/model-randomizer/SettingsPanel.vue:464

Related contextual observations

All four candidates are CSS style declarations inside a scoped SCSS block

low risk · high confidence

All four flags are on styling code, not program logic. The scanner mistook CSS layout rules for a security issue.

Technical assessment

All four flagged lines (458, 464, 473, 479) fall within the scoped SCSS style section of a Vue single-file component for a model randomizer settings panel. Each line defines a CSS layout class with standard display, flex, gap, and padding properties. There is no JavaScript execution, no persistence API call, no startup hook, and no data flow to any destination. The persistence scanner rule is matching on CSS property patterns unrelated to actual startup persistence modification.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity