TavernKeeper Scan Report

senjinthedragon/SillyTavern-Discord-Connector

Commit e3a2678 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 30 low

What this review found

No material or immediate-danger item was identified.

Deterministic technical evidence (22)
  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/publish.yml:30

  • zizmor reported cache-poisoning · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/publish.yml:30

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/persona-map.test.js:17

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/publish.yml:15

  • Dependency advisory GHSA-8xcm-r25x-g524:pkg:0e0e3ef7b07665812bdc5021 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: server/package-lock.json

  • Dependency advisory GHSA-h67p-54hq-rp68:pkg:0199d54d4e55594b20539f39 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-g8m3-5g58-fq7m:pkg:d10a1af9c865101c9cc1b09a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: server/package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:a2732cf17ea59b7c9ad7dcba applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/websocket-router.test.js:22

  • Dependency advisory GHSA-p88m-4jfj-68fv:pkg:efcee449c87d39d4db94186e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: server/package-lock.json

  • Dependency advisory GHSA-m8rv-5g2x-5cg5:pkg:dfdc5c12308ee863a661f110 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: server/package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:d9de591f6b7272d0d17e4e9f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/publish.yml:18

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/lang-map.test.js:17

  • Dependency advisory GHSA-v3r7-h72x-cjcm:pkg:78c671fc46b87817fdf1de6e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: server/package-lock.json

  • Dependency advisory GHSA-52cp-r559-cp3m:pkg:cf5cb3ae8e56cb4261cd5e98 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-35p6-xmwp-9g52:pkg:7cd7d8f74690ab75b37c197f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: server/package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:46968ba7f775ec580db4bbb2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-vxpw-j846-p89q:pkg:9fd432fe695c0d4b2a2a02dc applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: server/package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:4ccc458e17e9edf57fcb5743 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/plugin-i18n.test.js:17

  • zizmor reported cache-poisoning · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/publish.yml:18

Contextual expected matches (8)

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

The scanner thought the code was obfuscated, but the file is plain and readable. It's just a list of expression emojis.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code. The match applies to this repository.

Contextual assessment: JS-X-Ray reported an 'obfuscated-code' signal at line 1 of activity-format.js. The actual file contains well-documented, clearly readable JavaScript with comments, a constant map of emoji, and two simple functions. No obfuscation techniques (e.g., string encoding, dynamic execution, minification beyond normal) are present. The scanner signal is a false positive, possibly triggered by the emoji characters or the file header.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
production
Source
server/activity-format.js:1

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

This file downloads language translations from the server and uses them as simple text lookups, not as executable code. There is no security risk because the downloaded data is never run as code.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution. The match applies to this repository.

Contextual assessment: The file fetches JSON locale files from a hardcoded extension server path using fetch(). The fetched data is parsed as JSON and used as a plain string dictionary. No eval, new Function, or any dynamic code execution is performed on the fetched content. The interpolate() function only substitutes template placeholders with string values from a provided vars object. Therefore, the correlation between network retrieval and code execution is not actualized.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
production
Source
src/i18n.js:72-150

zizmor reported artipacked

Expected behavior · medium confidence

The scanner thought credentials might leak through build artifacts, but this workflow doesn't create any artifacts, so there's no risk.

Technical evidence

Scanner reason: zizmor matched workflow-security rule artipacked. The match applies to this repository.

Contextual assessment: The zizmor 'artipacked' rule flagged a potential credential persistence through GitHub Actions artifacts, but the workflow in publish.yml does not upload or store any artifacts. It only checks out the code and runs npm publish. No artifact upload step exists, so no credential persistence via artifacts is possible. The low scanner confidence and lack of actual artifact creation mean this is a false positive.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
zizmor 1.28.0
Rule
artipacked
File role
tooling
Source
.github/workflows/publish.yml:14-15

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The code checks whether the terminal supports colored output by looking at an environment variable. This is a normal and harmless operation for a server application.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: Line 55 reads process.env.TERM solely to determine terminal color support. This is a single, benign environment variable access with no credential or sensitive data exposure. The serialize-environment signal is triggered by the presence of process.env but no secrets are serialized or transmitted.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
server/websocket.js:55

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The extension has a default setting to connect to a server running on your own computer. This is necessary for the extension to work and is not a security concern.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: Line 27 defines a default WebSocket URL pointing to localhost (ws://127.0.0.1:2333). This is a standard configuration for a local bridge server. The 'shady-link' signal likely flags the ws:// protocol, but it is appropriate and expected for local socket communication. No external or suspicious URL is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
src/settings.js:27

Gitleaks reported discord-client-id

Expected behavior · high confidence

The flagged line is just a template example with fake numbers, not a real secret. It's there as a guide for users.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule discord-client-id. The match applies to this repository.

Contextual assessment: Gitleaks matched a Discord client ID pattern on a commented-out example line (discordChannelId: "123456789012345678") in an example configuration template. The value is a placeholder, not a real credential, and is part of the shipped example file users are instructed to copy and modify. No actual token or secret is exposed.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
discord-client-id
File role
production
Source
server/config.example.js:156

Gitleaks reported discord-client-id

Expected behavior · high confidence

The flagged line is just a template example with fake numbers, not a real secret. It's there as a guide for users.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule discord-client-id. The match applies to this repository.

Contextual assessment: Gitleaks matched a Discord client ID pattern on a commented-out example line (discordChannelId: "123456789012345678") in an example configuration template. The value is a placeholder, not a real credential, and is part of the shipped example file users are instructed to copy and modify. No actual token or secret is exposed.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
discord-client-id
File role
production
Source
server/config.example.js:165

JavaScript analysis reported javascript.xray.unsafe-import

Expected behavior · medium confidence

The code loads plugins from a user's configuration file. This is by design – if you add a plugin, it gets loaded. No outside attacker can inject plugin paths.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-import. The match applies to this repository.

Contextual assessment: JS-X-Ray flagged 'unsafe-import' at line 30 where plugin-loader.js uses `require(resolvedPath)` with a path derived from user configuration (config.externalPlugins). This is a legitimate plugin loader design: the user explicitly specifies external plugin modules (e.g., purchased pro plugins) in their local config file. No remote or user-supplied input from untrusted sources is involved; the configuration is local and controlled by the server administrator. The design is proportional to the project's purpose of supporting extensible frontends.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-import
File role
production
Source
server/plugin-loader.js:30

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity