TavernKeeper Scan Report

AMousePad/LumiRealm

Commit 3576f02 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 20 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-w4gp-fjgq-3q4g applies

Minor caution · low confidence

A security scanner found a known issue in one of the project's dependencies, but the scanner did not include which specific package is affected. Because this extension bundles only its final JavaScript output and most build-tool dependencies never reach end users, the practical risk is likely low. Updating dependencies is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-w4gp-fjgq-3q4g to a dependency declared by this repository.

Contextual assessment: OSV-scanner flagged a high-severity advisory against a dependency declared in the lockfile, but package details were removed from the scanner output, preventing precise identification of the affected package and version. The project bundles its output via Bun into dist/frontend.js, file, and dist/regex-runner.js; devDependencies such as esbuild, playwright, happy-dom, juice, and wasmoon do not ship to end users. Without knowing which package is affected, whether it is a production or development dependency, and whether attacker-controlled input reaches the vulnerable code path, no concrete user harm can be established. The advisory severity alone does not establish immediate danger.

Impact: low · Exploitability: unlikely

Developer action: Update dependencies to their latest patched versions where feasible. If the affected package is a devDependency, the risk is limited to the development environment.

Scanner
osv-scanner 2.4.0
Rule
GHSA-w4gp-fjgq-3q4g
File role
production
Source
bun.lock

Dependency advisory GHSA-v3r7-h72x-cjcm applies

Minor caution · low confidence

A scanner found a medium-level issue in a dependency, but did not specify which package. Since the extension only ships its bundled output and most tooling dependencies stay in the development environment, the practical risk is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v3r7-h72x-cjcm to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a lockfile dependency, but the affected package name and version were removed from scanner output. The project bundles its production output through Bun, meaning devDependencies do not ship to end users. The four production dependencies (fengari-web, fflate, tus-js-client, zod) would ship in the bundle, but without knowing which package this advisory targets, runtime reachability and attacker input control cannot be assessed. No concrete user harm is evident from the available evidence.

Impact: low · Exploitability: unlikely

Developer action: Update dependencies to patched versions when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v3r7-h72x-cjcm
File role
production
Source
bun.lock

Dependency advisory GHSA-g7r4-m6w7-qqqr applies

Minor caution · low confidence

A scanner found a low-level issue in a dependency but did not specify which package. The risk is minimal given the extension's bundling approach.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-g7r4-m6w7-qqqr to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was matched against a lockfile dependency with package details removed. The project bundles its output via Bun, so devDependencies do not reach end users. Without identifying the affected package, version, and whether it ships in the bundle, no concrete user harm or runtime reachability can be established. Low advisory severity further limits practical impact.

Impact: low · Exploitability: unlikely

Developer action: Update dependencies to patched versions when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-g7r4-m6w7-qqqr
File role
production
Source
bun.lock

Dependency advisory GHSA-35p6-xmwp-9g52 applies

Minor caution · low confidence

A scanner found a low-level issue in a dependency but did not specify which package. The risk is minimal.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-35p6-xmwp-9g52 to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was matched against a lockfile dependency with package details removed. The project bundles its production output, excluding devDependencies from the shipped artifact. Without the affected package identity, runtime reachability and attacker input control cannot be determined. No concrete user harm is evident.

Impact: low · Exploitability: unlikely

Developer action: Update dependencies to patched versions when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-35p6-xmwp-9g52
File role
production
Source
bun.lock

Dependency advisory GHSA-g8m3-5g58-fq7m applies

Minor caution · low confidence

A scanner found a low-level issue in a dependency but did not specify which package. The risk is minimal given the extension's bundling approach.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-g8m3-5g58-fq7m to a dependency declared by this repository.

Contextual assessment: A low-severity advisory was matched against a lockfile dependency with package details removed. The extension bundles its output through Bun, so development-only dependencies do not ship to end users. Without identifying the affected package, version, and shipping status, no concrete user harm or runtime reachability can be established.

Impact: low · Exploitability: unlikely

Developer action: Update dependencies to patched versions when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-g8m3-5g58-fq7m
File role
production
Source
bun.lock

Dependency advisory GHSA-8xcm-r25x-g524 applies

Minor caution · low confidence

A scanner found a medium-level issue in a dependency but did not specify which package. Since the extension only ships its bundled output, the practical risk is likely low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8xcm-r25x-g524 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a lockfile dependency with package details removed. The project bundles its production output via Bun, meaning devDependencies do not ship to end users. Without knowing which package is affected, whether it is a production or development dependency, and whether attacker-controlled input reaches the vulnerable code path, no concrete user harm can be established.

Impact: low · Exploitability: unlikely

Developer action: Update dependencies to patched versions when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8xcm-r25x-g524
File role
production
Source
bun.lock

Dependency advisory GHSA-m8rv-5g2x-5cg5 applies

Minor caution · low confidence

A scanner found a medium-level issue in a dependency but did not specify which package. The risk is likely low given the extension's bundling approach.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-m8rv-5g2x-5cg5 to a dependency declared by this repository.

Contextual assessment: A medium-severity advisory was matched against a lockfile dependency with package details removed. The project bundles its output through Bun, excluding devDependencies from the shipped artifact. Without the affected package identity, version, and shipping status, runtime reachability and attacker input control cannot be determined. No concrete user harm is evident from the available evidence.

Impact: low · Exploitability: unlikely

Developer action: Update dependencies to patched versions when available.

Scanner
osv-scanner 2.4.0
Rule
GHSA-m8rv-5g2x-5cg5
File role
production
Source
bun.lock

Dependency advisory GHSA-ph9p-34f9-6g65 applies

Minor caution · low confidence

A scanner found a high-level issue in a dependency but did not specify which package. Because this extension bundles only its final JavaScript output and most build-tool dependencies never reach end users, the practical risk is likely low. Updating dependencies is still recommended.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-ph9p-34f9-6g65 to a dependency declared by this repository.

Contextual assessment: A high-severity advisory was matched against a lockfile dependency, but package details were removed from the scanner output, preventing identification of the affected package and version. The project bundles its production output via Bun into dist/*.js files; devDependencies such as esbuild, playwright, tsx, happy-dom, juice, and wasmoon do not ship to end users. The four production dependencies (fengari-web, fflate, tus-js-client, zod) would ship in the bundle, but without knowing which package this advisory targets, runtime reachability and attacker input control cannot be assessed. Advisory severity alone does not establish immediate danger without confirmed shipping status and reachable vulnerable code.

Impact: low · Exploitability: unlikely

Developer action: Update dependencies to their latest patched versions. If the affected package is a devDependency, the risk is limited to the development environment. If it is a production dependency, verify whether the vulnerable code path is reachable in the extension's usage.

Scanner
osv-scanner 2.4.0
Rule
GHSA-ph9p-34f9-6g65
File role
production
Source
bun.lock

Dependency advisory GHSA-vxpw-j846-p89q applies

Minor caution · medium confidence

A known security issue was found in a dependency listed in the project's lock file. However, the project's actual shipped extension only includes a small set of core libraries, and this issue most likely lives in a development-only tool that never reaches end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-vxpw-j846-p89q to a dependency declared by this repository.

Contextual assessment: The lockfile declares four production dependencies (fengari-web, fflate, tus-js-client, zod) that are small, focused libraries with minimal transitive dependency trees. The dev dependencies (playwright, happy-dom, juice, tsx, wasmoon, esbuild platform packages) carry substantially larger transitive trees and are the more likely source of this advisory match. The project bundles its output via Bun for browser and Bun targets, so dev-only transitive dependencies are not included in the shipped extension artifacts. Without the specific package identity, runtime reachability in the shipped bundle cannot be confirmed, but the production dependency set makes it unlikely this advisory affects end users.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version if feasible. Confirm whether the advisory is in a production or dev-only dependency tree; if dev-only, no user-facing risk exists.

Scanner
osv-scanner 2.4.0
Rule
GHSA-vxpw-j846-p89q
File role
production
Source
bun.lock

Dependency advisory GHSA-37j7-fg3j-429f applies

Minor caution · medium confidence

A critical security alert was flagged in the project's dependency list. However, the project's shipped extension uses only a few small, well-known libraries, and this alert almost certainly comes from a development tool that is not included in the final product users install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-37j7-fg3j-429f to a dependency declared by this repository.

Contextual assessment: This critical-severity advisory was matched in the lockfile, but the four production dependencies (fengari-web, fflate, tus-js-client, zod) are compact libraries with negligible transitive trees and no known critical advisories at the declared versions. The critical match is far more likely to reside in a dev-only transitive tree such as playwright, happy-dom, juice, or esbuild. The build process bundles only production code into the shipped frontend and backend artifacts, excluding dev dependencies. Even if the advisory were in a production transitive dep, the extension runs inside the Lumiverse browser sandbox, limiting concrete user harm. The scanner removed package details, preventing definitive confirmation.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dev dependency to a patched version. Verify the advisory is not in a production dependency tree; if it is, assess runtime reachability in the bundled output.

Scanner
osv-scanner 2.4.0
Rule
GHSA-37j7-fg3j-429f
File role
production
Source
bun.lock

Dependency advisory GHSA-6q6h-j7hj-3r64 applies

Minor caution · medium confidence

A high-severity security issue was found in the dependency list, but it most likely comes from a development tool that is not part of the extension users actually install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-6q6h-j7hj-3r64 to a dependency declared by this repository.

Contextual assessment: Same lockfile context as the other candidates. The high-severity advisory most likely matches a transitive dependency of a dev-only package (playwright, happy-dom, juice, tsx, or esbuild platform binaries visible in the lockfile). The production dependency set is minimal and unlikely to carry this advisory. The shipped extension bundles only production code, so dev-only transitive vulnerabilities do not reach end users. Package identity was removed by the scanner, so exact confirmation is not possible from the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version. Confirm whether it is in a production or dev-only tree.

Scanner
osv-scanner 2.4.0
Rule
GHSA-6q6h-j7hj-3r64
File role
production
Source
bun.lock

Dependency advisory GHSA-p88m-4jfj-68fv applies

Minor caution · medium confidence

A medium-level security issue was found in the dependency list. It most likely comes from a development tool that does not ship with the extension, so users are probably not affected.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-p88m-4jfj-68fv to a dependency declared by this repository.

Contextual assessment: This medium-severity advisory was matched in the lockfile. Given the minimal production dependency set (fengari-web, fflate, tus-js-client, zod) and the larger dev-only trees (playwright, happy-dom, juice, tsx, esbuild), the match is more likely in a dev-only transitive dependency. The Bun bundling process excludes dev dependencies from shipped artifacts. Without the specific package identity, definitive reachability analysis is not possible, but the project structure strongly suggests no end-user impact.

Impact: low · Exploitability: unlikely

Developer action: Update the affected dependency to a patched version when convenient. Verify whether it is in a production or dev-only dependency tree.

Scanner
osv-scanner 2.4.0
Rule
GHSA-p88m-4jfj-68fv
File role
production
Source
bun.lock
Expected scanner matches (4)

Gitleaks reported generic-api-key

Expected behavior · high confidence

The scanner thought it found a secret password or API key, but the flagged text is just a list of command names used by the character-card compatibility feature. There is no real secret here.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: The flagged lines are string literals inside an array of known v2 opcode names for a RisuAI compatibility layer. They are identifier-like strings such as v2DeleteDictKey and v2HasDictKey, not credentials, tokens, or secrets. The gitleaks generic-api-key heuristic matched an identifier-like string, but the surrounding context shows no key material, no network destination, and no credential data flow.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
generated
Source
dist/backend.js:20406-20407

Gitleaks reported generic-api-key

Expected behavior · high confidence

The scanner saw the word 'Key' in a list of function names and flagged it as a possible password or API key. It is not a secret; it is just the name of a dictionary operation in the code.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: The gitleaks generic-api-key rule matched on a string literal inside an array of known v2 opcode names for the RisuAI compatibility layer. The matched lines are opcode identifiers such as v2DeleteDictKey and v2HasDictKey, which contain the substring 'Key' and triggered the heuristic. No secret value, credential, token, or API key is present; this is a static list of function names used for schema validation and opcode dispatch.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
generated
Source
dist/backend.js:19730-19731

Gitleaks reported generic-api-key

Expected behavior · high confidence

The scanner flagged what looks like a secret, but the text is just a list of command names used by the roleplay card system. There is no password or API key here.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: The flagged lines are string literals inside a constant array of opcode names for a RisuAI-compatible trigger script system. The gitleaks generic-api-key rule matched one of these opcode strings, but no secret value is present. This is a schema definition file containing enumerated command names, not credentials.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
production
Source
src/core/schemas/triggerscript.ts:77-78

Gitleaks reported generic-api-key

Expected behavior · high confidence

The scanner thought it found a secret password or API key, but the flagged text is just a list of command names for a scripting feature. There is no real credential here.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule generic-api-key in this repository.

Contextual assessment: The flagged lines 77-78 contain string literals within the KNOWN_V2_OPCODES array, listing opcode names such as dictionary variable operations for the RisuAI trigger script system. These are static constant identifiers used to validate or recognize supported script operations. No credential, secret, or sensitive value is present; the generic-api-key pattern produced a false positive on opcode naming conventions.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
generic-api-key
File role
production
Source
src/core/schemas/triggerscript.ts:77-78

Related contextual observations

Heuristic credential match on opcode name string literals

low risk · high confidence

A pattern scanner mistook ordinary command names for a secret key. No sensitive data is involved.

Technical assessment

The matched region is a string array of compatibility opcode identifiers. Identifier-shaped strings commonly trigger generic-api-key rules, but no secret value, assignment, transmission, or persistence is present.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Scanner removed package details for all eight dependency advisories, preventing precise reachability analysis

low risk · low confidence

The security scanner found eight dependency issues but did not include which specific packages are affected. This makes it impossible to determine which issues actually matter for end users versus which only affect the developer's build tools. The extension bundles its final output, so most build-tool dependencies never reach users. Updating all dependencies is the safest course of action.

Technical assessment

All eight OSV-scanner candidates have their package details removed from the scanner explanation, and the supplied source context covers only the first 41 lines of a 22KB lockfile. This prevents mapping each advisory to a specific package, version, and shipping status. The project declares four production dependencies (fengari-web, fflate, tus-js-client, zod) that would be bundled into the shipped extension, and several devDependencies (esbuild via tsx, playwright, happy-dom, juice, wasmoon, typescript) that would not ship. Without the package-to-advisory mapping, it is impossible to determine which advisories affect shipping code versus development-only tooling, whether vulnerable code paths are reachable at runtime, or whether attacker-controlled input reaches them. The assessments above reflect this uncertainty by assigning low confidence and low risk, since no concrete user harm can be established from the available evidence.

Impact: low · Exploitability: unlikely

Developer action: Run the scanner with package details enabled or manually cross-reference each GHSA ID against the lockfile to identify affected packages. Prioritize updating any production dependencies (fengari-web, fflate, tus-js-client, zod) that have advisories. DevDependency advisories can be addressed at lower urgency.

Sources:

Opcode name list triggers generic key heuristic

low risk · high confidence

A list of operation names includes words containing 'Key', which a scanner mistook for a leaked secret. No secret exists here.

Technical assessment

The KNOWN_V2_OPCODES array contains identifiers like v2HasDictKey and v2DeleteDictKey. The gitleaks generic-api-key rule keys on substrings resembling key material, producing a false positive on these opcode names.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Opcode name list triggers generic-api-key pattern

low risk · high confidence

A list of internal command names accidentally matched a secret-detection pattern. No actual secret exists in this file.

Technical assessment

The KNOWN_V2_OPCODES array contains string literals such as dictionary and variable operation names. One of these strings matched the gitleaks generic-api-key heuristic. The surrounding code is a static enumeration with no network calls, no variable assignment of secret material, and no runtime credential usage.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity