No material or immediate-danger item was identified.
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- character-sheet-validation.js:108
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- prose-guard-edits.js:292
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- index.js:3733
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- narration-sanitizer.js:67
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- scene-item-state.js:444
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- pre-flight.js:1199
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- semantic-extractor.js:344
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- deterministic-runner.js:3716
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- character-sheet-generation.js:183
Contextual expected matches (12)
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
This test builds a copy of one of the extension's own settings-migration functions using fixed sample data, just to check that it works. Nothing from the user, the chat, or the internet goes into it.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The flagged dynamic execution compiles a function whose body is assembled by slicing the project's own main script between two fixed function-name markers. The only injected values are local constants, a stub callback, and hardcoded test objects defined in the test itself. The compiled function is exercised purely through assertions with fixed inputs. No user-controlled, model-controlled, network, or stored configuration data flows into the generated code. The enclosing file is a standalone Node test runner using Node assertion and filesystem imports, and it is not the manifest-declared extension entry point, so it does not execute in the SillyTavern client. This is a legitimate test-isolation technique with no demonstrated exposure.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:20316-20324
JavaScript analysis reported javascript.xray.unsafe-regex
Expected behavior · high confidence
This is just a simple pattern matcher that reads a path format in a developer testing tool. Nothing about it can slow down the app or harm user data.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The flagged regex is a fixed literal used to parse dotted paths of the form relationshipEngine[name].subfield in a semantic evaluator. It contains no nested quantifiers or overlapping alternations; the negated character class [^\]]+ is matched linearly, so catastrophic backtracking is not possible. The reportPath values originate from in-repository golden fixture rule definitions rather than user or network input, and the module is a development evaluation utility. No ReDoS, injection, or exfiltration path is demonstrated.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
- Rule
- javascript.xray.unsafe-regex
- File role
- production
- Source
- semantic-golden-evaluator.mjs:44
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
Another test that reconstructs a widget-layout function from the extension's own code with fixed numbers and dummy helpers. Only test data is involved.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The flagged call constructs a function from a slice of the project's own main script and passes only numeric constants, arrow-function stubs, and object literals so the test can compare computed widget layout values against expected hardcoded results. The generated code body comes from the repository's committed source and every parameter is a fixed test double. There is no untrusted-input path, no runtime reachability outside the test suite, and no data destination beyond in-process assertion checks. This is consistent with the surrounding unit-test pattern rather than a dangerous execution path.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:20333-20348
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The test makes a simplified version of a function that finds the latest message of a certain type, using made-up sample messages. Nothing real or sensitive is touched.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The dynamic execution compiles a helper from a slice of the project's own source and injects two arrow functions defined inline in the test as providers, followed by assertions against a hardcoded array of message-like objects. All inputs are fixed test fixtures defined in the same file. The compiled source cannot be influenced by external parties, and the file is a repository-local Node test runner rather than the extension's declared browser entry point. No credentials, private content, or runtime environment state are involved, so the match reflects a test bootstrap rather than an exploitable code path.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:20325-20329
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The flagged eval-like code is inside the project's own test suite, where it builds a small test copy of a settings handler to verify that old settings are cleaned up correctly. It only uses fixed test values, so outside input cannot reach it and nothing leaves the test.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The dynamic function construction appears inside a self-test harness that extracts a small slice of the extension's own settings-migration routine and wraps it with a Function constructor using fixed, hard-coded fixture arguments. No scanner-visible user, model, or network-controlled data reaches the code string, and the constructed function is invoked only within the local test run to assert migration behavior. This is a legitimate test isolation technique rather than runtime code injection in shipped behavior, and no harmful data flow or destination is demonstrated.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:16891-16901
Gitleaks reported generic-api-key
Expected behavior · high confidence
The flagged secret is a made-up placeholder used in a test that checks whether the extension hides API keys in error messages. It is not a real password or key, and there is no evidence of an actual credential leak.
Technical evidence
Scanner reason: Gitleaks matched secret-detection rule generic-api-key. The match applies to this repository.
Contextual assessment: The credential scanner matched a deliberately constructed error-message fixture containing placeholder secret-looking tokens and an invalid example host. The surrounding test assertions verify that the diagnostic formatter redacts bearer tokens, API keys, and query-string keys, so the fixture is intentionally synthetic test data rather than a live credential. No real credential exposure, data flow, or runtime activation is demonstrated.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- gitleaks 8.30.1
- Rule
- generic-api-key
- File role
- production
- Source
- test-behavior.mjs:17390
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
This is test code that builds a small function from the project's own source to check its behavior. There is no user input involved and nothing hidden is being executed.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: This new Function call appears in a developer test harness. It compiles a source slice extracted from the repository's own index.js (from clampTrackerWidgetHeight to applyTrackerWidgetLayout) together with fixed numeric widget constants, then invokes the resulting layout math. The compiled source contains no user-controlled or runtime-supplied input, performs no I/O beyond the test itself, and the file is not loaded by the SillyTavern extension entry point. No attacker-controlled data flow into the generated code is demonstrated.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:11309-11318
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
This test isolates a small helper that clamps window sizes, feeding it plain numbers. There is no hidden behavior beyond checking the math.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The constructor body is another slice of the project's own main source, and the call site passes only numeric literals. The compiled function is used solely for assertions about dimension normalization behavior. There is no network, storage, secret, or user-input involvement, and the source text of the generated code originates from the repository's committed files. Consistent with the rest of the suite, this is reflective compilation inside a test harness with no attacker-controlled reachability and no demonstrated concrete harm.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:20308-20313
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
This test recreates a tiny settings-normalizing function from the project's own code and verifies it with a fixed list of mode names. It is purely a development check.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The flagged dynamic call compiles a function from a slice of the project's own source text and injects only a constant object mapping display-mode names. Subsequent assertions use string literals. The generated body cannot be influenced by external parties, and the containing file is a Node test harness that reads its own repository files and is not the manifest-declared extension entry point, so it does not run in the SillyTavern client. No data flow, destination, persistence, or disclosure concern is present; this is expected test-harness behavior.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:20304-20307
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
This test pulls the extension's own window-positioning functions into a simulated browser page and checks their math with fixed numbers and a fake screen. There is no real data, network, or user input involved.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: The flagged dynamic execution compiles several widget-geometry functions from a slice of the project's own main source and injects only numeric literals, a mocked viewport object, and a minimal document stub whose query selector returns either null or a fixed bounding rectangle. All subsequent use is limited to assertions on computed layout values. The generated code consists of the project's own functions and fixed test doubles, so there is no untrusted-input path and no reachability beyond the test suite. The containing file is a repository-local Node test runner and is not the manifest-declared extension entry point, so the code does not execute in the SillyTavern client. No exposure is demonstrated.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:20481-20496
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The test harness compiles a settings-migration function from the project's own code to verify it works. No outside data or hidden behavior is involved.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: This new Function call compiles migrateTrackerWidgetSettings sliced from the project's own index.js along with fixed constant definitions, then invokes it against test objects. All generated source content is derived from the repository's own source code and inline constants; there is no evidence that untrusted input can reach the code string. The call is confined to the test file execution path and demonstrates no persistence, network access, or credential handling.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:11319-11325
OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval
Expected behavior · high confidence
The test compiles an item-name formatter from the project's own code to check its behavior. It only runs in tests and has no connection to user data or the network.
Technical evidence
Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.
Contextual assessment: This new Function call builds formatTrackerItemDisplayName from a source slice of the repository's own index.js and invokes it with a hardcoded trimming callback. The code string is composed entirely from project source and fixed constants; no request data, message content, or model output is shown flowing into the compiled string. It is part of a test harness and not executed by the extension during normal SillyTavern operation. No malicious or exploitable behavior is demonstrated.
Impact: none · Exploitability: unlikely
Developer action: none
- Scanner
- opengrep 1.26.0
- Rule
- tavernkeeper.dynamic-execution.javascript-eval
- File role
- production
- Source
- test-behavior.mjs:11326-11329