TavernKeeper Scan Report

platberlitz/sillytavern-image-gen

Commit 59a58f6 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 49 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
lib/provider-capabilities.js:155

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
lib/provider-adapters.js:72

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
lib/generation-semantics.js:221

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
lib/hosted-provider.js:208
Deterministic technical evidence (23)
  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/a1111-runtime.test.js:48

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/security.test.js:16

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/comfyui-backend.test.js:341

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/server-relay-guards.test.js:21

  • JavaScript analysis reported javascript.xray.prototype-pollution · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: javascript-xray-structured-weakness · Execution scope: runtime

    Source: lib/custom-backend.js:26

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/provider-adapters.test.js:115

  • zizmor reported dangerous-triggers · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/notify-sillybunny.yml:3-8

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/settings-transfer.test.js:19

  • JavaScript analysis reported javascript.xray.unsafe-regex · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-unsafe-regex-inert · Execution scope: test-documentation-data

    Source: tests/manifest.test.js:13

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/hosted-provider.test.js:53

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/network-runtime.test.js:69

  • JavaScript analysis reported javascript.xray.prototype-pollution · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: javascript-xray-structured-weakness · Execution scope: runtime

    Source: lib/settings-transfer.js:13

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/provider-contract.test.js:16

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/client-orchestration.test.js:436

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/generation-run.test.js:23

  • JavaScript analysis reported javascript.xray.prototype-pollution · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: javascript-xray-structured-weakness · Execution scope: runtime

    Source: lib/image-metadata.js:749

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/image-metadata.test.js:399

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/gallery-repository.test.js:107

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/custom-backend.test.js:96

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/context-media.test.js:371

  • JavaScript analysis reported javascript.xray.prototype-pollution · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: javascript-xray-structured-weakness · Execution scope: runtime

    Source: lib/gallery-repository.js:80

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/hosted-provider.test.js:292

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: tests/server-relay-routes.test.js:57

Contextual expected matches (19)

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This code acts as a guard that stops the extension from fetching images from hidden internal or private network addresses, such as a home router or local computer. It is a protective check, not a way to send data anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The flagged network-access signal matches private-network host detection logic in a security utility module. The line classifies IPv6 loopback, unique-local, link-local, reserved, and IPv4-mapped IPv6 addresses so that requests to private hosts can be blocked during image-source normalization. This is defensive input validation with no network destination or data egress present in the supplied evidence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
lib/security.js:37

Gitleaks reported vault-service-token

Expected behavior · high confidence

This alert was triggered by accident. The line is just a label in a dropdown menu asking you to choose an image size setting, not a secret password or token.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule vault-service-token. The match applies to this repository.

Contextual assessment: Gitleaks flagged a vault-service-token pattern at line 17507, but the source context shows the line contains a static HTML option value string 'Crop and Resize' within a UI select element for IP-Adapter resize mode. No credential, token, or sensitive data is present. This is a textbook false positive from a generic pattern matching on common English words.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
vault-service-token
File role
production
Source
index.js:17507

Gitleaks reported vault-service-token

Expected behavior · high confidence

A security scanner thought it found a secret token in the code, but looking at the actual code shows only a normal slider setting for image detection sensitivity. No real password or key was exposed.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule vault-service-token. The match applies to this repository.

Contextual assessment: Gitleaks matched a 'vault-service-token' pattern at file line 17429, but the supplied source code at that line is a standard HTML input element for a confidence slider. No credential token, vault reference, or secret value is present in the evidence; the scanner's explanation confirms the matched value was removed. The detection is a false positive with no actual credential exposure.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
vault-service-token
File role
production
Source
index.js:17429

JavaScript analysis reported javascript.xray.unsafe-regex

Expected behavior · low confidence

The extension uses several fixed text-matching patterns to find character names in chat messages. These patterns are hard-coded and not based on user input, so they cannot be tricked into causing problems.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The static regex patterns at line 4736 are used by extractLikelyCharacterNames to match character name patterns in chat text. The patterns are not constructed from untrusted input; they are fixed literals defined in the source. JS-X-Ray flagged these as unsafe-regex, but no ReDoS or injection risk is demonstrated because the regexes are not dynamically built from attacker-controlled data and the input is already limited to chat text processed client-side.

Impact: low · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
index.js:4736

Gitleaks reported vault-service-token

Expected behavior · medium confidence

A security scanner thought it found a secret token on this line, but the line is actually just setting a image generation setting (resize mode). No real credential was exposed.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule vault-service-token. The match applies to this repository.

Contextual assessment: Gitleaks flagged a vault-service-token pattern at line 8457, but the actual source code shows an object property assignment for ControlNet unit configuration: `resize_mode: s.a1111IpAdapterResizeMode || "Crop and Resize"`. No credential, token, or secret appears in the surrounding context. The expansion text does not alter this conclusion. The scanner match is a false positive; the value removed by the scanner is not present in the raw source.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
vault-service-token
File role
production
Source
index.js:8457

Gitleaks reported vault-service-token

Expected behavior · high confidence

This alert was triggered by accident. The line is just a label in a dropdown menu asking you to choose an image size setting, not a secret password or token.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule vault-service-token. The match applies to this repository.

Contextual assessment: Gitleaks flagged a vault-service-token pattern at line 17506, but the source context shows the line contains a static HTML option value string 'Just Resize' within a UI select element for IP-Adapter resize mode. No credential, token, or sensitive data is present. This is a false positive from generic pattern matching.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
vault-service-token
File role
production
Source
index.js:17506

JavaScript analysis reported javascript.download-to-execution

Expected behavior · low confidence

The extension makes internet requests to image-generation services, which is exactly what it's supposed to do. There is no evidence that it downloads and runs code.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution. The match applies to this repository.

Contextual assessment: The code contains network retrieval (fetch) for image generation API calls, which is expected for an image generation extension. No dynamic code or command execution sink (eval, Function, child_process, etc.) was identified in the supplied evidence. The scanner's correlation is speculative and not substantiated by the actual code context. The project makes standard HTTP POST requests to configured image provider endpoints and does not execute fetched content as code.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
production
Source
index.js:1734-19574

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged code is the part that double-checks image links returned by AI image providers before downloading them. It only allows images from the expected provider websites, blocks insecure addresses, and never sends your API key to unknown servers. That is protective behavior, not anything sneaky.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The static 'shady-link' signal did not retain its matched literals and cannot be mapped to a malicious flow. The code at the flagged region builds URL objects with a localhost fallback base so that provider-returned image URLs can be resolved and validated before any fetch. isTrustedProviderOutputUrl rejects URLs with embedded credentials and non-HTTP(S) protocols, requires HTTPS with private hosts blocked via normalizeImageSource, matches output hosts against per-provider allowlisted suffixes, and optionally allows a single additional subdomain of a trusted HTTPS request host. The CivitAI output fetcher applies the same validation to both the initial and any redirect Location, refuses to forward the API key to non-orchestration hosts, and blocks redirects elsewhere. This is defensive allowlist handling of provider-controlled image URLs, consistent with the project's multi-provider image generation purpose, and does not demonstrate exposure of credentials or host data to untrusted destinations.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
lib/hosted-provider.js:37

Gitleaks reported vault-service-token

Expected behavior · high confidence

This alert was triggered by accident. The line is just a label in a dropdown menu asking you to choose an image size setting, not a secret password or token.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule vault-service-token. The match applies to this repository.

Contextual assessment: Gitleaks flagged a vault-service-token pattern at line 17508, but the source context shows the line contains a static HTML option value string 'Resize and Fill' within a UI select element for IP-Adapter resize mode. No credential, token, or sensitive data is present. This is a false positive from generic pattern matching.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
vault-service-token
File role
production
Source
index.js:17508

JavaScript analysis reported javascript.xray.sql-injection

Expected behavior · low confidence

The code creates settings controls for the extension. It looks like a database warning, but it's just building web page elements - no database commands are involved.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.sql-injection. The match applies to this repository.

Contextual assessment: Line 18210 contains a template literal used to build HTML for the extension's settings panel, which is then inserted into the DOM via insertAdjacentHTML. There is no SQL database, no SQL query construction, and no injection of user-controlled SQL syntax. JS-X-Ray's sql-injection signal is a false positive from the template literal syntax; the actual operation is client-side UI rendering with no database interaction.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.sql-injection
File role
production
Source
index.js:18210

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

A scanner thought the code might be intentionally hidden or scrambled, but the actual code is written clearly and openly. There is no hidden or malicious behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code. The match applies to this repository.

Contextual assessment: JS-X-Ray flagged file as potentially obfuscated with low confidence. The supplied evidence shows clean, well-structured JavaScript with standard module imports, constants, and helper functions. No obfuscation techniques (string encoding, control flow flattening, dead code, etc.) are visible. The detection is a false positive common in minified or large bundled code, but this project's source is not obfuscated.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
index.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The warning is about network activity in the custom image API code. Reading that code shows it is the opposite of suspicious: it checks that web addresses are safe, refuses to allow insecure connections when a secret key is used, and only talks to the image server you configured. Nothing found here sends your data anywhere secretly.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The JS-X-Ray 'shady-link' signal is a static heuristic and the matching literals were not retained, so it cannot be tied to a specific exfiltration pattern. The surrounding code is a defensive URL-safety layer for the Custom API image backend: isLoopbackUrl normalizes hostnames and validates IPv4 octets to recognize loopback destinations, assertSafeAuthDestination permits HTTP only for loopback URLs and otherwise enforces HTTPS when an API key is configured, and buildCustomBackendRequest sends the configured key only to the user-configured endpoint via bearer, header, query, or Basic auth. Response image URLs are fetched only after being normalized, having embedded credentials rejected, and being validated as HTTPS with private hosts blocked unless they share the request origin. Fetch calls use credentials omitted, redirect error, and no-referrer. This is consistent with the extension's stated purpose of supporting configurable custom image APIs (including local A1111/ComfyUI) and contains no evidence of data exfiltration or concealed network behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
lib/custom-backend.js:371

Gitleaks reported vault-service-token

Expected behavior · high confidence

A security scanner incorrectly flagged a line of code as containing a secret, but it's actually just a number input field in the settings panel. Nothing sensitive is exposed.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule vault-service-token. The match applies to this repository.

Contextual assessment: The gitleaks scanner flagged line 17417 under the vault-service-token rule, but the actual code is an HTML template input element for a numeric configuration setting (ADetailer confidence threshold). No credential, token, or secret is present on that line. The pattern match is a false positive arising from the template syntax, and no credential exposure or security-relevant data flow exists.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
vault-service-token
File role
production
Source
index.js:17417

zizmor reported artipacked

Expected behavior · high confidence

A workflow security tool warned that credentials might leak through saved build files, but this project's workflow never saves any files, so there is no way for credentials to leak that way.

Technical evidence

Scanner reason: zizmor matched workflow-security rule artipacked. The match applies to this repository.

Contextual assessment: Zizmor's artipacked rule flagged potential credential persistence through artifacts at lines 27-28 of .github/workflows/ci.yml. The workflow performs only checkout, dependency installation, code verification, and a dependency audit. It does not upload or store any GitHub Actions artifacts, and no GITHUB_TOKEN or other credential is exposed to artifact upload. The scanner confidence was low, and the full workflow content confirms no artifact-related risk exists.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
zizmor 1.28.0
Rule
artipacked
File role
tooling
Source
.github/workflows/ci.yml:27-28

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This extension creates and uses URLs to connect to image generation services, which requires building addresses dynamically. The code includes many checks to make sure those addresses are safe, like making sure they point to the expected service and not to a private or malicious location. This is expected for an extension that talks to many different image providers.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The extension contains 37 occurrences of JS-X-Ray's 'shady-link' signal, which flags dynamic URL construction. The code legitimately builds URLs from user-configured provider endpoints, proxy URLs, and image sources to make image generation API requests and to resolve, validate, and normalize image URLs. Every URL construction path is accompanied by origin checks, private-host blocking, and protocol validation (e.g., normalizeImageSource, corsFetch, shouldInlineAutoProxyRefUrl). The signals are proportional to the extension's stated purpose of supporting 18 image-generation backends plus custom APIs, and no evidence of exfiltration, hidden destinations, or bypass of validation was found.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
index.js:282

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This is the part of the extension that downloads the pictures returned by the image service. It only sends API keys to the service it is talking to, blocks unsafe links, and refuses redirects, so the evidence does not show secret-stealing or other unexpected behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The static network-access signal corresponds to provider-image URL handling in an image-generation extension. The module parses image sources returned by provider APIs, normalizes them, and conditionally fetches HTTPS image URLs as part of the extension's stated purpose. Credential headers are only attached when the resolved image host matches the originating provider origin or an explicitly allowlisted credential origin/host; redirects are rejected, response sizes are bounded, and private hosts are blocked for untrusted sources. No data flow to an unexpected destination is shown in the supplied evidence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
lib/provider-adapters.js:409

JavaScript analysis reported javascript.xray.encoded-literal

Expected behavior · high confidence

The scanner flagged a long code-like string, but it is just the official model version identifier the extension uses to make sure the right image model is selected. It is not hidden code or anything malicious.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.encoded-literal. The match applies to this repository.

Contextual assessment: The encoded-literal signal matches a long hexadecimal constant used as a pinned Replicate SDXL model version identifier. It is a public model version string used to validate user configuration against the supported model, not concealed data or obfuscated runtime behavior. The surrounding functions compare configured version strings to this constant and return descriptive validation errors, which is normal configuration handling for a provider integration.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.encoded-literal
File role
production
Source
lib/provider-capabilities.js:250

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The warning points to a fallback address using 'localhost' that is only used when the page's own address cannot be read. This extension needs to turn a reference image the user picks into a format the local image generator accepts, and fetching that image is the only network action here. The code checks the image type and size first, and nothing sensitive is sent anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The scanner signal matches a fixed localhost fallback used only as the base URL when resolving a user-supplied reference image for a local image backend. The flagged literal appears solely as the default when the page address is unavailable, so in normal browser operation the current page URL is used instead. The function then restricts the resolved source to data URLs or HTTP(S) URLs, enforces a byte size limit, verifies the image signature before use, and delegates retrieval to an injected reader not present in this file. No credentials or private content leave this code, and the only network behavior is fetching the image the user chose so it can be embedded into a local generation request. This matches the stated purpose of an image-generation extension that supports a local backend. The scanner pattern is known to flag localhost literals, so the finding is consistent with a false positive rather than any demonstrated exposure.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
lib/a1111-runtime.js:50

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged line creates a label used to manage CORS proxy state for local image tools and also checks that configured server addresses are safe, requiring secure connections except for your own computer. This is routine bookkeeping for network requests, not a hidden connection to a suspicious destination.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The flagged region contains getCorsProxyStateKey, which parses a target URL with a localhost fallback base and derives a deterministic string describing origin, method, mode, credentials policy, and content-type class. It is a cache/proxy state key builder and does not itself issue any network request or transmit data. The same file's assertSafeConfigurableEndpoint enforces HTTP(S)-only endpoints, rejects embedded credentials, and requires HTTPS for non-loopback destinations, which supports local tools such as A1111/ComfyUI while preventing plaintext credential transit to remote hosts. The URL constructs with a localhost fallback are correct for the SillyTavern local-server context and are the likely source of the static heuristic match. No attacker-controlled input path, secret destination, or exfiltration flow is demonstrated.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
lib/network-runtime.js:80

Related contextual observations

Static scanner signal is a false positive for this extension's design

low risk · high confidence

The security scanner flagged many places where the code builds web addresses. However, these are all normal places where the extension needs to create URLs to talk to image services, and it has safety checks built in.

Technical assessment

The 37 'shady-link' occurrences are concentrated in URL-handling functions that are essential for the extension's operation: resolving provider API endpoints, normalizing image sources from inbound messages, constructing proxy requests, and building URLs for gallery and background images. The scanner's pattern-based detection does not account for the validation logic (origin pinning, private-IP blocking, trusted-base-url checks) that precedes each URL construction. This is a known limitation of static analysis for this class of extension.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Fixed regex patterns may cause performance issues on very large inputs

low risk · medium confidence

The text-matching patterns might be slow if someone pastes a very long message, but they can't be used to cause harm beyond a temporary slowdown.

Technical assessment

The regex patterns in extractLikelyCharacterNames have consecutive alternations and word-boundary checks that could exhibit quadratic worst-case behavior on extremely long strings. However, the input is chat text (typically a few hundred to a few thousand characters) and the patterns are not attacker-controlled. The impact is limited to a potential client-side slowdown, not a security vulnerability.

Impact: low · Exploitability: unlikely

Developer action: Consider simplifying or anchoring the regex patterns to reduce theoretical worst-case complexity, though no exploit is known.

Sources:

Plain HTTP reference resolution is proportionate to local backend support

low risk · medium confidence

Allowing normal HTTP image links makes sense because the local image generator this extension talks to usually runs on the user's own computer over plain HTTP. Only the user-chosen reference image is fetched, and the code verifies it is a real image of acceptable size.

Technical assessment

Reference image resolution permits plain HTTP URLs and relative paths alongside HTTPS and data URLs. This is proportionate because the supported local image backend commonly listens on a plain HTTP local address and user-provided reference images may live on ordinary pages. Retrieval is delegated to an injected reader, the resolved URL is scheme-checked, a byte limit is enforced, and the image signature is validated before returning encoded bytes. The supplied evidence shows no attacker-controlled destination and no unintended data flow.

Impact: none · Exploitability: unlikely

Developer action: No change required. If browser mixed-content rules become a problem, document that the local backend should use HTTPS or that reference images should come from an HTTPS source.

Sources:

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity