No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger
0 material
2 low
What this review found
No material or immediate-danger item was identified.
Minor cautions
JavaScript analysis reported javascript.download-to-execution
Minor caution · high confidence
The extension loads a markdown-rendering library from a public CDN at runtime. This is a common practice but means the extension depends on an external service. If the CDN were ever compromised, the loaded code would run with the user's permissions. There is no sign of malicious intent.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: low · Exploitability: unlikely
Developer action: Bundle marked.js locally instead of loading from CDN to eliminate the external dependency risk.
Scanner javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule javascript.download-to-execution
File role production
Source index.js:6-143
Related contextual observations
Remote CDN script load for marked.js library
low risk · high confidence
Detailed wording was omitted by the public report safety filter.
Technical assessment
Detailed technical wording was omitted by the public report safety filter.
Impact: low · Exploitability: unlikely
Developer action: Bundle marked.js locally instead of loading from CDN to eliminate the external dependency risk.
Sources:
Coverage and limitations
Inventory 6 files · 55909 bytes
Contextual coverage 1 of 1 candidates assessed
JavaScript coverage
Status Complete
Candidates 1 files · 31726 bytes
X-Ray review families 0 warning occurrences compacted to 0 evidence-preserving review families
Representations 1 raw · 0 decoded · 0 normalized · 0 bundle modules
Stage scans 1 raw signatures · 1 raw AST · 1 raw OpenGrep · 0 derived signatures · 0 derived AST · 0 derived OpenGrep
Tools
Limitations
This advisory review cannot prove the absence of unknown behavior.
Technical scan identity
Full commit b8cde7c92696fd68e0ffd668057c9d001b2d31ba
Completed Aug 24, 2026
History depth 20 commits
Method Deterministic evidence with contextual review
Reviewer nano-gpt.com · zai-org/glm-latest
Scanner 0.1.0
Scanner policy 5
Rule catalog 2
Contextual policy 5
Ecosystem context sillytavern-community-v1
Prompt contextual-review-v7
Assessment schema contextual-assessment-v2
Review provenance 1 fresh / 0 reused groups · 1 fresh / 0 reused candidates
Review source reports none
Evidence triage 0 deterministic / 1 contextual candidates · 1 contextual / 1 total behavior cases
Model budget 1 model call · 1 / 12 fresh cases · 21073 / 200000 estimated input · 17073 / 250000 actual input · 1229 / 40000 output tokens
Review batching 1 model call · up to 1 groups and 1 candidates per call · 0 retry calls · 0 over-budget singleton calls
Review usage 17073 input · 1229 output · 1472 cache read · 0 reasoning tokens
Report 3af104ade1e5c29b99a9e0fabd10cd2057ab8eea3482f70b91d1e6167fa20863