No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger
0 material
1 low
What this review found
No material or immediate-danger item was identified.
Contextual expected matches (1)
JavaScript analysis reported javascript.xray.shady-link
Expected behavior · high confidence
The scanner saw a web address in the code and flagged it. The address is just the standard identifier that all SVG images must include; it is not a website the code contacts. The line creates a tiny blank placeholder image entirely inside the browser with no network activity.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
Scanner javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule javascript.xray.shady-link
File role production
Source src/modules/avatar-gallery/index.js:1029
Coverage and limitations
Inventory 28 files · 377817 bytes
Contextual coverage 1 of 1 candidates assessed
JavaScript coverage
Status Complete
Candidates 18 files · 304366 bytes
X-Ray review families 1 warning occurrences compacted to 1 evidence-preserving review families
Representations 18 raw · 1 decoded · 0 normalized · 0 bundle modules
Stage scans 18 raw signatures · 18 raw AST · 18 raw OpenGrep · 1 derived signatures · 0 derived AST · 1 derived OpenGrep
Tools
Limitations
This advisory review cannot prove the absence of unknown behavior.
Technical scan identity
Full commit 2205d1d0576acc3dcbcef4d1b0a472c283d4a9ad
Completed Aug 24, 2026
History depth 6 commits
Method Deterministic evidence with contextual review
Reviewer nano-gpt.com · zai-org/glm-latest
Scanner 0.1.0
Scanner policy 5
Rule catalog 2
Contextual policy 5
Ecosystem context sillytavern-community-v1
Prompt contextual-review-v7
Assessment schema contextual-assessment-v2
Review provenance 1 fresh / 0 reused groups · 1 fresh / 0 reused candidates
Review source reports none
Evidence triage 0 deterministic / 1 contextual candidates · 1 contextual / 1 total behavior cases
Model budget 1 model call · 1 / 12 fresh cases · 21113 / 200000 estimated input · 16649 / 250000 actual input · 649 / 40000 output tokens
Review batching 1 model call · up to 1 groups and 1 candidates per call · 0 retry calls · 0 over-budget singleton calls
Review usage 16649 input · 649 output · 1472 cache read · 0 reasoning tokens
Report 75396f1ecde09b1d743b81e9e1c8c24345d502c669a50c1fe085356d5991f246