What this review found
No material or immediate-danger item was identified.
Minor cautions
Dependency advisory GHSA-g7r4-m6w7-qqqr applies
Minor caution · high confidence
The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-g7r4-m6w7-qqqr to a dependency declared by this repository.
Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected development dependency to a patched version to keep the build environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-g7r4-m6w7-qqqr
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-rf6f-7fwh-wjgh applies
Minor caution · high confidence
The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rf6f-7fwh-wjgh to a dependency declared by this repository.
Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected development dependency to a patched version to keep the build environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rf6f-7fwh-wjgh
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-3v7f-55p6-f55p applies
Minor caution · high confidence
The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.
Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected development dependency to a patched version to keep the build environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3v7f-55p6-f55p
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-3jxr-9vmj-r5cp applies
Minor caution · high confidence
The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.
Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected development dependency to a patched version to keep the build environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-3jxr-9vmj-r5cp
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-jxxr-4gwj-5jf2 applies
Minor caution · high confidence
The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-jxxr-4gwj-5jf2 to a dependency declared by this repository.
Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected development dependency to a patched version to keep the build environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-jxxr-4gwj-5jf2
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-f886-m6hf-6m8v applies
Minor caution · high confidence
The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.
Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected development dependency to a patched version to keep the build environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-f886-m6hf-6m8v
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-rgw5-rvv9-x895 applies
Minor caution · high confidence
The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.
Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected development dependency to a patched version to keep the build environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-rgw5-rvv9-x895
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-4x5r-pxfx-6jf8 applies
Minor caution · high confidence
The flagged tool is used only by the developer to build or test the extension. It is not part of the final product that users install, so it does not pose a risk to users.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.
Contextual assessment: The lockfile shows the project's direct runtime dependencies are limited to React UI components. The advisory corresponds to a development or build-time dependency. Because the extension ships a pre-built bundle, development dependencies are not executed in the user's browser. The vulnerable code has no runtime reachability for end users.
Impact: none · Exploitability: unlikely
Developer action: Update the affected development dependency to a patched version to keep the build environment secure.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-4x5r-pxfx-6jf8
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-2p49-hgcm-8545 applies
Minor caution · low confidence
A security scanner flagged a dependency in this project's lockfile as having a known vulnerability. This extension is a visual theme for SillyTavern with no access to passwords, API keys, or server functions, so the practical risk to users is low. The flagged package is most likely a build tool that never runs on end-user machines.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-2p49-hgcm-8545 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency resolved in bun.lock. The project is a frontend-only SillyTavern UI theme extension that ships compiled dist/bundle.js and dist/style.css. The visible direct dependencies are React UI libraries and the devDependencies are build tooling (Vite, ESLint, Tailwind, etc.). Without the specific package identity it is not possible to confirm runtime reachability, but the project has no server-side component, no credential handling, and no external API calls in its stated purpose. Advisory severity alone does not establish user harm in this context.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient, but no urgent action is required for this frontend-only extension.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-2p49-hgcm-8545
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-c2c7-rcm5-vvqj applies
Minor caution · low confidence
Another dependency in the lockfile was flagged. Since this is a purely visual extension and the flagged package is likely a development or build tool, the real-world danger to people using the extension is minimal.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in bun.lock. The extension ships only compiled frontend assets. The project purpose is a Discord-themed UI overlay for SillyTavern with no credential, network, or persistence capabilities beyond standard UI rendering. The advisory's severity does not by itself demonstrate exploitable runtime reachability in this deployment model.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-c2c7-rcm5-vvqj
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-r28c-9q8g-f849 applies
Minor caution · low confidence
A third dependency was flagged by the scanner. The extension is a theme with no sensitive data access, so the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency resolved in bun.lock. The project is a frontend UI theme with compiled output. No evidence of server-side processing, credential handling, or attacker-controlled input reaching vulnerable code paths is present in the supplied context.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-r28c-9q8g-f849
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-mh99-v99m-4gvg applies
Minor caution · low confidence
A fourth dependency was flagged. As with the others, this is a visual extension with no sensitive functions, so the risk to users is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a high-severity advisory against a dependency in bun.lock. The extension is a compiled frontend theme for SillyTavern. The advisory severity does not translate to user harm without runtime reachability and attacker-controlled input, neither of which is evident in this frontend-only project.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-mh99-v99m-4gvg
- File role
- production
- Source
- bun.lock
Dependency advisory GHSA-fxqj-rqcc-2cmp applies
Minor caution · low confidence
A medium-severity dependency flag was raised. This extension is a visual theme with no access to sensitive data, so the practical risk is low.
Technical evidence
Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.
Contextual assessment: OSV-scanner matched a medium-severity advisory against a dependency in bun.lock. The project is a frontend-only UI theme extension shipping compiled assets. No runtime reachability or attacker-controlled input path is evident in the supplied context for this advisory to produce concrete user harm.
Impact: low · Exploitability: unlikely
Developer action: Update the affected dependency to a patched version when convenient.
- Scanner
- osv-scanner 2.4.0
- Rule
- GHSA-fxqj-rqcc-2cmp
- File role
- production
- Source
- bun.lock
Expected scanner matches (2)
Gitleaks reported generic-api-key
Expected behavior · high confidence
The scanner thought it found a secret password or key, but the flagged line is just normal code that sets up the extension's public interface. There is no hidden credential here.
Technical evidence
Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- gitleaks 8.30.1
- Rule
- generic-api-key
- File role
- production
- Source
- src/apis/extensionAPI.ts:499
Gitleaks reported generic-api-key
Expected behavior · high confidence
The scanner flagged this line because it saw words that look like they could be related to API keys. However, the line is just a code definition describing how the extension's API works. There is no secret or password here.
Technical evidence
Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.
Contextual assessment: The gitleaks generic-api-key rule matched on line 31, which contains a TypeScript type annotation declaring a property named api of type DiscordiaAPIv1 within an interface definition. This is a static type declaration in source code, not a hardcoded credential, token, or secret value. No sensitive data is present, and the matched text is a type reference with no runtime credential exposure.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- gitleaks 8.30.1
- Rule
- generic-api-key
- File role
- production
- Source
- src/apis/extensionAPI.ts:31