TavernKeeper Scan Report

mechamarmot/SillyTavern-PyRunner

Commit 78d8f55 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 40 low

What this review found

No material or immediate-danger item was identified.

Deterministic technical evidence (33)
  • Dependency advisory GHSA-v6h2-p8h4-qcjw:pkg:954583494f7b71625ae8e6ee applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:30da7db405d2e49715cb0ed6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:567c541f015fe4079ca9b17e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:2f8d75dd087c1050a99a8192 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4c8g-83qw-93j6:pkg:181d5c1a6aff27dd93f86cff applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4x5r-pxfx-6jf8:pkg:5d05d295ab71b8b28f6cf3e2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-23c5-xmqv-rm74:pkg:28c6f8e6010383b649a97a01 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-h67p-54hq-rp68:pkg:0199d54d4e55594b20539f39 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:c6056f5a45897dd10bfacade applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:a2732cf17ea59b7c9ad7dcba applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v39h-62p7-jpjc:pkg:a6be302000b0d22d393bcd4e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fv7c-fp4j-7gwp:pkg:31e02f2120b5c9c2060db33d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-38r7-794h-5758:pkg:965faedb9e1a3d6a2b7f06ee applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3ppc-4f35-3m26:pkg:173c1b2fab8e025126fb982c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7r86-cg39-jmmj:pkg:fa706fb036ae029fca4e7e55 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:9600c6310040af533d8d1920 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r5fr-rjxr-66jc:pkg:acc54e333efad0fdcbcc3646 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-q3j6-qgpj-74h6:pkg:2d0d5c8fc1bb62c4e3b44b2a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-qj8w-gfj5-8c6v:pkg:7d87d343aa0c80bd7734851a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8fgc-7cc6-rx7x:pkg:c7b736e220f17155bfcb5c14 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2g4f-4pwh-qvx6:pkg:8950845d54c4e7bb7af09309 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2g4f-4pwh-qvx6:pkg:e75f751e62b1e8418f7d80f3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-52cp-r559-cp3m:pkg:cf5cb3ae8e56cb4261cd5e98 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rf6f-7fwh-wjgh:pkg:1ad66953e1a5c36ecde1d7df applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2g4f-4pwh-qvx6:pkg:cad7e9fb17eb5405be0d1fe2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-25h7-pfq9-p65f:pkg:27d1ccf82c346af697c968b5 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-xxjr-mmjv-4gpg:pkg:e49a21569220bc1e9110dc78 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-f886-m6hf-6m8v:pkg:db05cad6d25aec0390d39a8c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5c6j-r48x-rmvq:pkg:9695ebfe7ac51867550b15ed applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-c2c7-rcm5-vvqj:pkg:09f761f2e2a83fdc7890eb5a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3v7f-55p6-f55p:pkg:972939a004a2a625fbda61c7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-48c2-rrv3-qjmp:pkg:a2b2de1b67a6232727d04ad2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-f23m-r3pf-42rh:pkg:bf40c9910aa3de0f3855d6c9 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

Contextual expected matches (7)

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

This extension is designed to run Python code you write, either in your browser using Pyodide (a safe sandbox) or on your computer using your own Python. It loads the Pyodide library from a known CDN, which is normal. The scanner warning is because it downloads something and then runs code, but that's exactly what it's supposed to do.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The extension loads Pyodide from a fixed CDN URL via document.createElement('script') and executes user-provided Python code via pyodide.runPython() in browser mode, or sends code to a local server that spawns a Python child process. Both the network retrieval and dynamic code execution are core, documented features of the extension (see README). The CDN URL is hardcoded and not attacker-controlled. The user must explicitly enable the extension and supply code. No evidence of exfiltration, hidden behavior, or malicious intent.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
generated
Source
dist/index.js:1

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

The extension sets up its features when SillyTavern starts, which is how all extensions work. It doesn't change any startup files or install anything without your knowledge.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The extension registers a server plugin via init(router) and uses SillyTavern's standard event system (eventSource, saveSettingsDebounced) for settings persistence. This is normal SillyTavern extension behavior. There is no modification of startup scripts, system files, or SillyTavern's own startup process. The scanner rule matched a generic pattern but the actual behavior is routine extension initialization, not malicious persistence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

This extension loads Python for use in the browser from a preset internet address, which is necessary for its functionality.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The loadScript function dynamically loads Pyodide from a hardcoded HTTPS URL (cdn.jsdelivr.net/pyodide/v0.24.1/full/pyodide.js). This is the intended mechanism to load the WebAssembly Python runtime in the browser and is required for Pyodide execution mode. The URL is fixed and not attacker-controlled.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
generated
Source
dist/index.js:9-162

JavaScript analysis reported javascript.opengrep.tavernkeeper.persistence.startup-modification

Expected behavior · medium confidence

The extension contains a text copy of its server-side code, but does not use it to change how the program starts or behaves.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.opengrep.tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: The rule matched a long string literal assigned to variable k. That string contains the complete source code of the server-side Node.js plugin (which imports child_process, path, fs). However, this string is not executed, eval'd, or used to modify startup behavior; it is embedded for reference or transmission to the server process. No evidence of unauthorized persistence or startup modification.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.opengrep.tavernkeeper.persistence.startup-modification
File role
generated
Source
dist/index.js:493

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The extension sends your computer's environment variables to the Python scripts you choose to run. This is normal for running code, and the extension warns you that server mode is dangerous.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The extension passes the full host process environment to spawned Python child processes to ensure compatibility and access to system paths, which is standard for code execution tools. The project explicitly warns users about the dangers of server-mode execution. No evidence of exfiltration or misuse is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
server-plugin/index.js:300

JavaScript analysis reported javascript.xray.suspicious-literal

Expected behavior · low confidence

A scanner thought something looked off, but the actual code is normal for a bundled extension.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.suspicious-literal in this repository.

Contextual assessment: JS-X-Ray flagged a literal value as suspicious, but the provided code consists entirely of standard webpack/babel helper polyfills and intended extension logic. No obfuscation, concealment, or malicious literal patterns are evident in the examined source.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.suspicious-literal
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

The extension sends Python code you write from your browser to the SillyTavern server on your own computer, which then runs the code. This is how the extension is supposed to work. The code is not sent anywhere else.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The client-side code in file contains `fetch` calls to the local server plugin endpoints (e.g., `/install`, `/execute`) and the server plugin executes Python code. This is the intended architecture of the extension: the client sends Python code to the local server, and the server runs it. The network destination is the local SillyTavern server plugin endpoint, not an arbitrary external URL. The execution sink (Python execution) is the core feature. The static scanner pattern "download-to-execution" is a false positive because the communication is local and controlled.

Impact: low · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
production
Source
src/index.js:245-541

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity