TavernKeeper Scan Report

CarlosNahuelcoy/SillyTavern-Player2

Commit fae29f2 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 1 low

What this review found

No material or immediate-danger item was identified.

Contextual expected matches (1)

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged link is a plain-HTTP address pointing only to the user's own computer (127.0.0.1) on port 4315. This is the local mode for talking to the Player2 desktop app, which is exactly what the extension says it does. There is no secret or suspicious destination involved.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
index.js:11

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity