No material or immediate-danger item was identified.
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- character-sheet-validation.js:108
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- pre-flight.js:1235
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- scene-item-state.js:443
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- deterministic-runner.js:852
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- index.js:3804
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- narration-sanitizer.js:67
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- prose-guard-edits.js:294
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- character-sheet-generation.js:183
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- semantic-extractor.js:425
Contextual expected matches (12)
JavaScript analysis reported javascript.xray.unsafe-regex
Expected behavior · high confidence
An automated scanner thought a text-matching rule in the project's own test tool might hang on crafted input. The rule is actually simple and finishes quickly, it only ever processes the project's own test data, and this tool runs only when a developer runs it locally, not when the extension is used.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The flagged pattern-match expression resolves dotted report paths against a ledger object inside a standalone golden-output evaluation script. Examining the expression itself, it consists of a literal prefix, one negated character class, and a single greedy wildcard segment; there are no nested quantifiers or interleaved alternations that could produce exponential backtracking, so the scanner heuristic does not correspond to a real catastrophic-backtracking condition. The matched input originates from the project's own committed fixture rules rather than attacker-controlled data, and the file executes only as a local command-line evaluation harness, not in the SillyTavern extension runtime.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- semantic-golden-evaluator.mjs:44
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
A scanner flagged code that writes code at runtime. In this test file, the tests take the extension's own code from the repository and wrap pieces of it in small throwaway functions so they can be exercised outside the browser. Nothing a user or outsider provides ever flows into this process, and this file only runs when a developer runs the test suite locally, never when the extension is installed and used.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The flagged dynamic function construction appears in a Node-based behavior test harness, not in the script the extension manifest loads at runtime. The test reads the extension's committed entry script from disk, slices out pure widget size and position clamping helpers, compiles them into isolated testable units, and invokes them with synthetic viewport dimensions. The only content ever compiled is the project's own already-executable source; no chat text, network data, saved configuration, or other untrusted input reaches the constructor. An adversary able to alter that committed source would already possess arbitrary code execution in the project, so this construction introduces no new execution path, destination, or persistence.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:11983-11989
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The flagged code is part of the developer's own testing script. It copies a few math-only layout functions out of the extension's main file and runs them with fake screen sizes to check that on-screen panels position and resize correctly. The only code it ever runs is the project's own, already-public source; nothing from users, chats, or the internet is executed. This is a normal way to test a hobby project, not a hidden or dangerous behavior.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: Detailed technical wording was omitted by the public report safety filter.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:22661-22676
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
This is the same testing pattern flagged again: the tests pull one of the extension's own helper functions out of its source file and run it against made-up settings values to confirm it fixes bad data. It only ever uses the project's own code and only runs during local development testing.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: This flagged dynamic function construction sits in the same local test harness and compiles the project's own settings-migration helper extracted from the committed entry script, then calls it with synthetic malformed settings objects to verify defaults are repaired. The compiled content is entirely repository-authored source, the invocation is developer-initiated test execution, and no untrusted or user-controlled data reaches the constructor. There is no network retrieval, obfuscation, or runtime path from the SillyTavern extension into this code.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:11973-11982
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
One more instance of the same test technique: a formatting helper from the extension's own code is wrapped in a temporary function and checked with a simple stand-in routine. Only the project's own code is involved, and only when a developer runs the tests.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: This third flagged construction follows the identical pattern in the same test harness: an item display-name formatter extracted from the project's committed entry script is compiled for isolated testing and invoked with a developer-supplied stub sanitizer. The sole input to the dynamic construction is the repository's own source text, execution occurs only when the developer runs the test suite, and the extension manifest never loads this file. No attacker-influenced data flow, concealed execution, or additional capability is demonstrated.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:11990-11993
Gitleaks reported generic-api-key
Expected behavior · high confidence
The scanner saw text that resembles an API key, but it is a deliberately made-up sample used by a test that verifies the program hides secret-looking text from error messages. It is not a real key, and nothing sensitive is exposed.
Technical evidence
Scanner reason: Gitleaks matched secret-detection rule generic-api-key. The match applies to this repository.
Contextual assessment: The matched line is a synthetic fixture inside the self-test harness. It fabricates an error message containing placeholder credential-shaped strings and a reserved example-invalid endpoint, then asserts that the diagnostic formatter redacts all of them before anything is displayed or logged. The strings are invented markers with no connection to any real account or service; the test exists specifically to prove credential-like text is scrubbed from diagnostics. No current or usable secret is present, and the fixture never leaves the test run.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- gitleaks 8.30.1
- Rule
- generic-api-key
- File role
- production
- Source
- test-behavior.mjs:18591
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
This is a test that lifts one function out of the project's own code and runs it by itself with fake inputs, to check that obsolete settings get cleaned up correctly. The security scanner flags the technique used to run the code, but the only code being run is the project's own, so there is no way for an outsider to sneak anything in through it.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The flagged dynamic construction sits inside the project's self-test harness. That harness reads the project's own committed main script from disk, extracts a single settings-migration function by index boundaries, compiles it with the Function constructor, and invokes it with locally defined mock arguments to verify retired settings are removed and the save routine runs exactly once. The executed text originates solely from the repository's own source file; no user chat content, remote data, or environment input flows into the executed string. The dynamic compilation runs only when the test harness is invoked, not during normal extension generation, and the extension manifest loads only the main script.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:17781-17793
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The project's self-check test pulls one of its own helper functions out of its main script and runs it in isolation with stand-in values to confirm the widget placement math is correct. Only the project's own code is executed, nothing from users, chats, or the internet. This is a harmless testing technique.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The matched construct builds a function at runtime inside the project's behavior test suite. The test reads the extension's own entry script from disk, extracts the widget layout calculator by name, and evaluates that excerpt with numeric constants, simple stub helper closures, a stubbed viewport object, and panel preference values in order to assert layout math. The only input to the dynamically evaluated code is the project's own committed first-party source plus literals defined in the test itself. There is no path from chat content, model output, network data, user input, or credentials into the evaluated code, no network access, no persistence, and no obfuscation. The extension manifest declares only the entry script for loading, so this file has no role in the SillyTavern runtime. The scanner matched the dynamic-execution capability; capability alone is not evidence of danger, and here it is a test-harness technique with no untrusted data flow.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:22513-22528
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The project's test file takes one of its own lookup functions and runs it with simple fake data to verify it finds the right entry. Nothing from outside the project is executed, so there is no safety concern.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The matched construct builds a function at runtime inside the behavior test suite. The test extracts the latest handoff-entry lookup from the extension's own entry script and evaluates that excerpt with two small stub predicates that operate on plain in-test message objects. The evaluated code is first-party committed source only; no chat content, model output, network data, credentials, or other untrusted input reaches it, and no network, persistence, or obfuscation is involved. The file is a test harness and is not referenced by the extension manifest's loading entry point, so it does not execute in the SillyTavern runtime. The scanner flag reflects the dynamic-execution pattern, not a demonstrated exposure.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:22505-22509
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The project's test file runs one of its own number-checking helpers with a few sample numbers to confirm the size limits work. Only the project's own code runs, so this is harmless.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The matched construct builds a function at runtime inside the behavior test suite. The test extracts the saved-dimension normalizer from the extension's own entry script, evaluates it with no injected dependencies, and asserts expected clamping results using literal numeric arguments. The evaluated code is exclusively first-party committed source; there is no untrusted input path, network access, credential handling, persistence, or obfuscation. The construct lives in a standalone test file that the extension manifest does not load. The dynamic-execution match reflects a test technique, not a demonstrated exposure.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:22488-22493
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The project's test file runs one of its own settings-upgrade functions with fixed sample values to make sure saved preferences convert correctly. Nothing outside the project's own code is executed, so there is no risk to users.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The matched construct builds a function at runtime inside the behavior test suite. The test extracts the settings migration routine from the extension's own entry script and evaluates that excerpt with the previously built normalizer, literal version and size constants, a panel preference map, and a trivial coordinate stub, so the migration logic can be exercised against known inputs. The evaluated code derives entirely from the project's own committed source and test literals; no user, chat, model, or network data flows into it, and no credentials, persistence, network calls, or obfuscation are present. The test file is not part of the runtime entry point declared by the extension manifest. The scanner match identifies the dynamic-execution pattern, not a concrete exposure.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:22496-22504
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The project's test file takes one of its own small setting-checking functions and runs it with sample values to confirm invalid settings fall back correctly. Only the project's own code runs, so this is not a threat.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The matched construct builds a function at runtime inside the behavior test suite. The test reads the extension's own entry script from disk, extracts the display-mode normalizer by name, and evaluates that excerpt with a stubbed constants object representing the two supported display modes. The executed code is first-party committed source only; the surrounding assertions verify mode normalization with literal arguments. No chat content, model output, network data, credentials, or user-controlled input reaches the evaluated code, and there is no network access, persistence, or obfuscation. The file is a standalone test harness that the extension manifest does not load into the SillyTavern runtime. The dynamic-execution flag reflects the mechanism, not demonstrated exposure.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:22484-22487