TavernKeeper Scan Report

Sagesheep/NarrativeEngine-P

Commit 3c3ed4f Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 100 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex in this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
server/lib/modLoader.js:82

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex in this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
server/lib/nlp.js:76
Deterministic technical evidence (73)
  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/chapterRoutes.test.js:66

  • JavaScript analysis reported javascript.xray.obfuscated-code · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: mobile/scripts/buildNameBank.mjs:1

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/archiveRollbackCleanup.test.js:16

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: vite.config.ts:18

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/modLoaderScreens.test.js:21

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/fixtureRoundtrip.test.js:3

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/archiveScopedSearch.test.js:3

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:c301f7c72c558e741e2a83a0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/archiveRollbackCleanup.test.js:29

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:5549e38f839c3aff7a893c01 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: packages/engine/package-lock.json

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:f94edd69deef3d5effba7f8b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:a74a840ed39e2c344447a144 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: packages/engine/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/fixtureRoundtrip.test.js:12

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/archiveAppend.test.js:40

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/backup.test.js:3

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/tts.test.js:12

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/measure-tables-gate.mjs:52

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/modLoader.test.js:12

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:c301f7c72c558e741e2a83a0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: packages/engine/package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:5fa4bd8083566590384ce4fc applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/vectorStore.test.js:2

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: src/utils/__tests__/openRouterImage.test.ts:23

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:590275f7f1e65a0bda08b540 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/archiveAppend.test.js:3

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:a74a840ed39e2c344447a144 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.unsafe-regex · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-unsafe-regex-inert · Execution scope: tooling-only

    Source: mobile/scripts/gate.mjs:62

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:5549e38f839c3aff7a893c01 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/archiveSurgical.test.js:45

  • Dependency advisory GHSA-m8rv-5g2x-5cg5:pkg:effd824192445928106e41b7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • Dependency advisory GHSA-4cwx-7wf7-3272:pkg:1176429e737cfabdf766cdff applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/tableRegistry.test.js:12

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/modTableRegistry.test.js:31

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/modLoaderPanels.test.js:23

  • Dependency advisory GHSA-f88m-g3jw-g9cj:pkg:ecf7e487f6a9797646947cf8 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/vectorStore.test.js:13

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/sceneImages.test.js:16

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/archiveAppend.test.js:247

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/enemyCompendium.test.js:2

  • Dependency advisory GHSA-xcpc-8h2w-3j85:pkg:d5eec46a16e206bae715f821 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.crypto.weak-algorithm · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: javascript-xray-structured-weakness · Execution scope: runtime

    Source: server/lib/fileStore.js:206

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/sceneImages.test.js:3

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/modsRoute.test.js:8

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/chaptersWO06.test.js:13

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/modTableRegistry.test.js:9

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/archiveScopedSearch.test.js:43

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/tableRegistry.test.js:3

  • Dependency advisory GHSA-r292-9mhp-454m:pkg:9c48992b21aae7684fbb8f78 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:96b0a287af3567603b1e7088 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/chapterRoutes.test.js:3

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/modTableRoutes.test.js:23

  • Dependency advisory GHSA-8xcm-r25x-g524:pkg:9efcb22ccad71d16e9fbb4db applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:f06446b68aa7f55d2eb73400 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:bcb01fa3f22fe943388f7142 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/modTableRoutes.test.js:13

  • Dependency advisory GHSA-v3r7-h72x-cjcm:pkg:2f99006f4e2ddba635fa3089 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/comfyUiProvider.test.js:123

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/chaptersWO06.test.js:3

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/sceneImages.test.js:23

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/vault.test.js:3

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/measure-tables-gate.mjs:31

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/tts.test.js:2

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.sql-injection · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: javascript-xray-structured-weakness · Execution scope: runtime

    Source: server/lib/vectorStore.js:188

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:6e817d0e74f5357b4ff6f7ff applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/archiveSurgical.test.js:3

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/verify-screen-frame.mjs:475

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:01b2133f8343a79cb37d38d0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/backup.test.js:19

  • Dependency advisory GHSA-jr45-8vmc-qm54:pkg:ef6cbe09bba3516afec0221f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: mobile/package-lock.json

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/__tests__/comfyUiProvider.test.js:26

Contextual expected matches (25)

JavaScript analysis reported javascript.xray.data-exfiltration

Expected behavior · high confidence

The scanner flagged a line of code that decodes text, thinking it might be stealing data. But it's just a normal part of how the program handles text—no data is being sent anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.data-exfiltration in this repository.

Contextual assessment: The scanner signal at line 39 matches a String.fromCharCode pattern within the UTF-8 decoder utility, a standard part of the Emscripten WASM glue code. This is an encoding function, not a data exfiltration primitive. No evidence of sending data to an external destination.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.data-exfiltration
File role
production
Source
mobile/public/ort/ort-wasm-simd-threaded.mjs:39

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This is a test script that talks to itself on your own computer. It does not connect to the internet.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The scanner flagged a literal URL pattern within this test file, which connects to a localhost page server and a local CDP debug interface. All network targets are loopback addresses, the connection is entirely internal to the test harness, and the signal originates from the tooling-only verification script that is never shipped with the application. There is no data sent to an external server.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
tooling
Source
scripts/verify-sandbox.mjs:24

Gitleaks reported generic-api-key

Expected behavior · high confidence

This is a test that checks whether the app's encryption properly hides secret keys. The 'secret' shown is just a fake placeholder used for testing, not a real key.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: The gitleaks match is on a test file that uses a placeholder string `[REDACTED_SECRET:18b87face90d]` to verify the encryption function does not leak the plaintext into ciphertext. This is a characterization test for a security property. The string is not a live credential; it's a synthetic test value that was already redacted by the scanner output.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
test
Source
src/services/infrastructure/__tests__/settingsCrypto.test.ts:291

JavaScript analysis reported javascript.xray.unsafe-command

Expected behavior · high confidence

The script uses 'taskkill' to clean up a test browser after testing — it is safe and expected.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-command in this repository.

Contextual assessment: Line 129 is a call to spawn('taskkill.exe', ...) in terminateProcessTree(). This is a test cleanup utility that kills child browser processes. The PID comes from the script's own child process, not from user input. This is standard test infrastructure, not an exploitable command injection.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-command
File role
tooling
Source
scripts/verify-screen-frame.mjs:129

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The app sets environment variables to control where it stores its text-to-speech model files. This is a normal setup step and not a security concern.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The scanner flagged process.env assignments used to configure Hugging Face cache directories for a local TTS model. All values are hardcoded to a local data subdirectory, not user-controlled or sent externally. This is a standard workaround for a third-party library limitation and poses no credential theft risk.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
server/lib/tts.js:67

JavaScript analysis reported javascript.xray.data-exfiltration

Expected behavior · high confidence

The code reads your computer's name and username to create a secret key that locks your API keys to your machine. This information stays on your computer and is never sent anywhere. It's a normal and expected part of a local password manager.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.data-exfiltration in this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.data-exfiltration
File role
production
Source
server/vault.js:4

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The script is testing that a security sandbox correctly hides sensitive information. It tries to see if it can find pretend API keys, and that is the intended behavior of the test.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The serialize-environment signal matches a test fixture that intentionally probes for credential patterns within sandboxed workers. The code serializes a mock context object and checks for API key patterns to verify that the sandbox prevents credential leakage. This is a deliberate part of the sandbox validation test, not an actual exfiltration attempt.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
scripts/verify-sandbox.mjs:257

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

When the app runs as a desktop program, it needs to know where to find its own backend. It uses a fixed address that points to the same computer — nothing is sent over the internet.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The file defines API_BASE and ASSET_BASE constants using an absolute localhost URL for Electron production builds where relative paths fail under file:// protocol. The URLs point to the application's own local Express server on loopback, not an external or untrusted host. This is a legitimate architectural choice for a self-hosted Electron app.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
src/lib/apiBase.ts:10

JavaScript analysis reported javascript.xray.data-exfiltration

Expected behavior · high confidence

The scanner found a pattern that looks like data theft in a complex generated file. But this file is a standard part of the AI model library (ONNX Runtime) that runs models locally on your computer. The flagged code just coordinates worker threads and wasm loading — it does not steal or send away any data.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.data-exfiltration in this repository.

Contextual assessment: JS-X-Ray flagged a 'data-exfiltration' signal in the auto-generated Emscripten/ONNX Runtime WebAssembly glue code. The lines at and around line 60 contain worker message routing and promise management that are standard parts of the ONNX Runtime threading support. The file (ort-wasm-simd-threaded.asyncify.mjs) is a build artifact from the @huggingface/transformers library used for local embedding models. The data flows are internal to the wasm runtime (loading models, transferring tensor data between workers). No credential or user data is exfiltrated. The static analysis signal is a false positive.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.data-exfiltration
File role
production
Source
mobile/public/ort/ort-wasm-simd-threaded.asyncify.mjs:60

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

This file is a safety test that tries to reach the internet and checks that it correctly fails; it does not actually use any downloaded data in a dangerous way.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: This tooling-only fixture tests that network requests are blocked by CSP; fetch, XHR, and WebSocket results are only used to record blocked status, not to execute retrieved content. There is no download-to-execution path.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
tooling
Source
scripts/screen-frame-fixtures/escape-net.js:27-46

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

The scanner saw code that downloads a file and runs it, but that's how the ONNX AI model runtime loads its engine—it's like downloading a plugin file to run. The app is supposed to do this to work correctly.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The file contains a fetch() call to download a .wasm binary and passes it to WebAssembly.instantiate(). This is the standard loading mechanism for ONNX Runtime WebAssembly modules. The network retrieval fetches only the trusted ORT wasm binary from a same-origin or local file path, and instantiation is a controlled code execution that runs the pre-compiled wasm. No arbitrary dynamic code execution (eval, Function) is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
production
Source
mobile/public/ort/ort-wasm-simd-threaded.mjs:4-15

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The app correctly restricts which websites can talk to it. Only the app itself and the local development server are allowed.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The scanner flagged a string literal containing a localhost URL in a CORS allowlist. The application is a self-hosted server bound to 127.0.0.1 and only allows requests from Electron file-based origins or the Vite development server. This is standard deplatforming behaviour, not a suspicious link.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
server.js:59

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

This file is a practice test used to make sure that the app correctly blocks add-ons from reaching the internet. It tries to access a harmless website on purpose to check if the block works. It is not part of the real app.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: This file is a test fixture located in a sandbox test directory. It exports an async function that checks whether the fetch function is defined and then calls fetch on a benign example URL. The function returns a result object indicating whether the call succeeded or was blocked. The file is not included in production builds and is only used to verify that the mod sandbox correctly restricts network access. There is no dynamic code execution sink, such as eval or exec, present. The correlation flagged by the scanner between network retrieval and a code execution sink is not applicable here; the sole purpose is to test sandbox escape prevention.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
fixture
Source
src/services/mods/sandbox/__tests__/fixtures/escape-net.js:1-7

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The script binds a test server to localhost — that is normal and safe.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: Line 52 is a server.listen() call binding to '127.0.0.1'. The 'shady-link' signal is a false positive — this is a local loopback bind, not an external or suspicious link.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
tooling
Source
scripts/verify-screen-frame.mjs:52

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

This code is an automatically generated part of the ONNX AI runtime that runs inside your browser. The flagged 'dynamic execution' is just how the runtime talks to the WebAssembly module — it is not running any user-controlled code.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.

Contextual assessment: This file is Emscripten-generated JavaScript glue code for the ONNX Runtime WebAssembly module (ort-wasm-simd-threaded.asyncify.mjs). The dynamic execution signal at line 49 corresponds to Emscripten's internal function call dispatch, including 'new Function(...)' used for method caller generation (Pb function) and emval dynamic dispatch. These are standard runtime constructs for WebAssembly interop and are not used to execute user-provided or untrusted code. The file is a well-known component of the @microsoft/ort-web package.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
production
Source
mobile/public/ort/ort-wasm-simd-threaded.asyncify.mjs:49

JavaScript analysis reported javascript.xray.unsafe-command

Expected behavior · high confidence

The script launches a web browser as part of a test, and later cleans it up. Only the developer running the test triggers this, and it only affects their own machine.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-command in this repository.

Contextual assessment: The unsafe-command signal corresponds to a controlled use of child_process.spawn to launch Microsoft Edge in headless mode for sandbox testing, and to spawn taskkill.exe for process cleanup. All spawned processes are part of the test infrastructure, run with hardcoded or local-address arguments, and are not reachable by untrusted input. The scanner correlation is a false positive in this tooling context.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-command
File role
tooling
Source
scripts/verify-sandbox.mjs:129

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

The script downloads test data from its own local server and launches a browser to test it — both are controlled by the developer, not by an attacker.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The 'download-to-execution' correlation between fetch (to localhost) and spawn (to launch a browser) is intentional. The script creates a local HTTP server, polls it for JSON, and spawns a headless browser for testing. All network destinations are loopback and attacker-unreachable. No untrusted input flows to the execution sink.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
tooling
Source
scripts/verify-screen-frame.mjs:70-212

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

The script downloads nothing from the internet and only runs commands that a developer would run to test the security features. It is not a real threat.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The file contains both network fetch calls (to localhost debug endpoints) and system command spawn calls (to start and kill a browser process). Both are integral to the automated sandbox verification test and operate exclusively on internal loopback addresses. The same-file correlation is expected for this test harness and does not represent a download-to-execution attack path.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
tooling
Source
scripts/verify-sandbox.mjs:42-211

JavaScript analysis reported javascript.xray.data-exfiltration

Expected behavior · high confidence

The app checks your computer's CPU and memory to recommend settings, which is done on your own machine and not sent anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.data-exfiltration in this repository.

Contextual assessment: The signal 'data-exfiltration' flagged the use of os.cpus() and os.totalmem() in the /api/system/specs endpoint. This endpoint provides host hardware information (CPU cores, memory) to the client for suggesting indexing speed. The data is served locally over localhost and is not exfiltrated. This is a legitimate feature of the application.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.data-exfiltration
File role
production
Source
server/routes/embedding.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The security scanner flagged a web address that is actually just a standard technical label used to draw graphics; no data is sent to that address.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The flagged line is a constant string assigned to SVG_NS used for creating SVG elements via createElementNS; it does not initiate any network request and is standard practice.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
mods/skill-tree.screen.js:163

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

The scanner flagged that this file downloads some code (a .wasm file) and then runs it. That is exactly what this file is supposed to do — it's the runtime that loads the AI model to run locally on your device. The download is from the same server where the app itself lives, not from a suspicious source.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The scanner correlated a network retrieval primitive (fetch/XMLHttpRequest) with a code execution sink (WebAssembly.instantiate, Worker.postMessage) in the same file. This is expected behavior for an Emscripten-generated runtime: it loads the .wasm binary via fetch and instantiates it, and it spawns pthread workers with postMessage to run model inference in parallel. The file is part of the ONNX Runtime WebAssembly distribution, a widely used dependency. The network requests target the same-origin .wasm file bundled with the application, not external or attacker-controlled destinations.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
production
Source
mobile/public/ort/ort-wasm-simd-threaded.asyncify.mjs:5-18

Gitleaks reported generic-api-key

Expected behavior · high confidence

The scanner flagged a fake API key used only in an automated test that checks whether the password-encryption code works correctly. It's not a real credential and is never used in the actual app.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: The Gitleaks detection matched a placeholder API key string in a unit test file (settingsCrypto.test.ts). The test intentionally includes redacted secret values to validate that the encryption module (settingsCrypto) correctly encrypts and never leaks the plaintext apiKey into ciphertext. The test verifies that the ciphertext does not contain the original secret. This is a standard security characterization test and the value is not a real credential. The file role is test-documentation-data and the secret is not shipped or executed in production.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
test
Source
src/services/infrastructure/__tests__/settingsCrypto.test.ts:291

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The app reads an optional environment variable to set its data folder location, which is normal and safe.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment in this repository.

Contextual assessment: The scanner signal 'serialize-environment' flagged the line exporting DATA_DIR from process.env.DATA_DIR. This is a standard configuration pattern that allows overriding the data directory via environment variable. No credentials or secrets are read; it is a directory path. This is expected behavior for a self-hosted application.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
server/lib/fileStore.js:10

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The app downloads images from your chosen AI image service and saves them to your campaign folder, which is expected behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The signal 'shady-link' flagged the data URI detection at line 178. The code handles image generation API responses that may return a data:image/ URI. It correctly decodes the base64 data after stripping the data URL prefix and validates the resulting binary is a known image format (PNG, JPEG, WebP, GIF). This is standard processing for AI image generation results. No suspicious link is present.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
server/services/imageProvider.js:178

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The flagged web address is part of a safety test that tries to reach a local server to confirm it is correctly blocked; it is not malicious.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: The flagged URL is a test fetch to the app's own local API endpoint used to verify CSP blocks; the response is only recorded as a probe outcome. This is legitimate tooling behavior.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
tooling
Source
scripts/screen-frame-fixtures/escape-net.js:46

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity