TavernKeeper Scan Report

Sillyanonymous/SillyTavern-UIShortcuts

Commit 2205d1d Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 1 low

What this review found

No material or immediate-danger item was identified.

Contextual expected matches (1)

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The scanner saw a web address in the code and flagged it. The address is just the standard identifier that all SVG images must include; it is not a website the code contacts. The line creates a tiny blank placeholder image entirely inside the browser with no network activity.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
src/modules/avatar-gallery/index.js:1029

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity