No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger
0 material
4 low
What this review found
No material or immediate-danger item was identified.
Minor cautions
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
Scanner javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule javascript.xray.unsafe-regex
File role production
Source src/state.js:275
Deterministic technical evidence (3)
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/test.yml:27
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/test.yml:30
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/test.yml:26-27
Coverage and limitations
Inventory 34 files · 505593 bytes
Contextual coverage 4 of 4 candidates assessed
JavaScript coverage
Status Complete
Candidates 22 files · 202282 bytes
X-Ray review families 1 warning occurrences compacted to 1 evidence-preserving review families
Representations 22 raw · 2 decoded · 0 normalized · 0 bundle modules
Stage scans 22 raw signatures · 22 raw AST · 22 raw OpenGrep · 2 derived signatures · 0 derived AST · 2 derived OpenGrep
Tools
Limitations
This advisory review cannot prove the absence of unknown behavior.
Technical scan identity
Full commit 3740cf228e1f8e6e6171501cf230885ad9a7e21f
Completed Aug 31, 2026
History depth 2 commits
Method Deterministic evidence with contextual review
Reviewer Not used — deterministic policy
Scanner 0.1.0
Scanner policy 5
Rule catalog 2
Contextual policy 5
Ecosystem context sillytavern-community-v1
Prompt contextual-review-v7
Assessment schema contextual-assessment-v2
Review provenance 0 fresh / 0 reused groups · 0 fresh / 0 reused candidates
Review source reports none
Evidence triage 4 deterministic / 0 contextual candidates · 0 contextual / 2 total behavior cases
Model budget 0 model calls · 0 / 12 fresh cases · 0 / 200000 estimated input · 0 / 250000 actual input · 0 / 40000 output tokens
Review usage 0 input · 0 output · 0 cache read · 0 reasoning tokens
Report 1862d6469bd95cc29bbc74fff0edc07a2f9531d05d7e6615a587620c58496b26