No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger
0 material
4 low
What this review found
No material or immediate-danger item was identified.
Minor cautions
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
Scanner javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule javascript.xray.unsafe-regex
File role production
Source src/state.js:275
Deterministic technical evidence (3)
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/test.yml:27
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/test.yml:30
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/test.yml:26-27
Coverage and limitations
Inventory 33 files · 495400 bytes
Contextual coverage 4 of 4 candidates assessed
JavaScript coverage
Status Complete
Candidates 21 files · 196026 bytes
X-Ray review families 1 warning occurrences compacted to 1 evidence-preserving review families
Representations 21 raw · 2 decoded · 0 normalized · 0 bundle modules
Stage scans 21 raw signatures · 21 raw AST · 21 raw OpenGrep · 2 derived signatures · 0 derived AST · 2 derived OpenGrep
Tools
Limitations
This advisory review cannot prove the absence of unknown behavior.
Technical scan identity
Full commit 25de9378bcac0470824a77d1d537e6b30042a2a2
Completed Aug 20, 2026
History depth 20 commits
Method Deterministic evidence with contextual review
Reviewer Not used — deterministic policy
Scanner 0.1.0
Scanner policy 5
Rule catalog 2
Contextual policy 5
Ecosystem context sillytavern-community-v1
Prompt contextual-review-v7
Assessment schema contextual-assessment-v2
Review provenance 0 fresh / 0 reused groups · 0 fresh / 0 reused candidates
Review source reports none
Evidence triage 4 deterministic / 0 contextual candidates · 0 contextual / 2 total behavior cases
Model budget 0 model calls · 0 / 12 fresh cases · 0 / 200000 estimated input · 0 / 250000 actual input · 0 / 40000 output tokens
Review usage 0 input · 0 output · 0 cache read · 0 reasoning tokens
Report 25c344172c93609c1b315e8c85920a6fa19753434f6511e2e0a6d6ebbe07bace