TavernKeeper Scan Report

TCLowe1982/Marinara-Extender

Commit e2ac670 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 57 low

What this review found

No material or immediate-danger item was identified.

Deterministic technical evidence (41)
  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: memory-extender/src/__tests__/security.test.ts:28

  • Dependency advisory GHSA-8j4g-w8fx-2239:pkg:3e467d8947b7f246d7090b8c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-g7r4-m6w7-qqqr:pkg:49d70202ab5a1e786e48c24f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:c9523a0885d757426ed83e80 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: memory-extender/scripts/backfill-attribution.mjs:39

  • Dependency advisory GHSA-f23p-vx2j-j53r:pkg:8ca91679ace53f3fc0187ffd applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-4xrf-jv44-h6hh:pkg:249ffb00fffad7006fcf485a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-v3r7-h72x-cjcm:pkg:56a7523636fdad742b465963 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-xgm2-5f3f-mvvc:pkg:67d9eeec4e7fe47300b75840 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:678d4d4a8016db80660c8069 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-8xcm-r25x-g524:pkg:21482577a9f354a102a52248 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-p88m-4jfj-68fv:pkg:2c9b270cbdff9249b9445785 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/repair-recap-pairing.mjs:29

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:6f926e74aaf2969f045549e9 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-79qm-7rj5-m7r9:pkg:f22e76bf7e577254be886f2e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:1c043fdb9ddfee4f4331dbb0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-frvp-7c67-39w9:pkg:682033ccbfda6cc7860c37a3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: memory-extender/scripts/backfill-beats-entries.ts:18

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: memory-extender/scripts/backfill-scene-facts.mjs:31

  • Dependency advisory GHSA-22jq-vg5j-6vgg:pkg:9eb93abfae910113d9babee3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-mwp4-54f8-5fhr:pkg:dbb007cbd7ab30b0c5bafbe0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:32565e5915130b51271b4195 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-c96f-x56v-gq3h:pkg:22d45e26f5c2ba711de22b7a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • JavaScript analysis reported javascript.xray.unsafe-regex · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-unsafe-regex-inert · Execution scope: test-documentation-data

    Source: memory-extender/src/__tests__/update.test.ts:39

  • Dependency advisory GHSA-w62v-xxxg-mg59:pkg:e12e3cf78cb874ae6863c270 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: memory-extender/scripts/reconcile-queue.mjs:40

  • Dependency advisory GHSA-54fx-42gc-7vw4:pkg:14191056c0fc735262e32e4a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-vxpw-j846-p89q:pkg:f643971b599393bf30cbc67d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: memory-extender/scripts/repair-indexes.mjs:21

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: memory-extender/scripts/reconcile-facts.mjs:50

  • Dependency advisory GHSA-v6wh-96g9-6wx3:pkg:a723a0b877739b2df5d9673f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: memory-extender/src/__tests__/security.test.ts:25

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: memory-extender/scripts/reconcile-sweep.mjs:43

  • Dependency advisory GHSA-g8m3-5g58-fq7m:pkg:9d7a6ea4726dcca5dc843ea7 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: memory-extender/src/__tests__/update.test.ts:46

  • Dependency advisory GHSA-fx2h-pf6j-xcff:pkg:6df69dc1690d731305cb014f applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-hvrm-45r6-mjfj:pkg:a79c6045f84b330cd9bfc38e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-m8rv-5g2x-5cg5:pkg:5f69b30b06991e290cede667 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-35p6-xmwp-9g52:pkg:672e530e9c56bae1329846bd applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-4c8g-83qw-93j6:pkg:a90c096b0a189e0f49499767 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:d681b9f3617b82bd6b835445 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: memory-extender/package-lock.json

Contextual expected matches (15)

OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline

Expected behavior · high confidence

A README file shows a command users can run to install Beads. The extension does not run this command itself — it's just documentation.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline in this repository.

Contextual assessment: The scanner matched a curl-pipe-bash command inside a documentation file (file) that describes installing Beads. The command is instructional text, not executable code in the extension. The extension itself never executes this command; it is a standard installation pattern shown to users. No runtime execution path or attacker-controlled input is involved.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.download-and-execute.shell-pipeline
File role
documentation
Source
.beads/README.md:64-65

OpenGrep reported tavernkeeper.credential-exfiltration.javascript-secret-to-network

Expected behavior · high confidence

A security scanner flagged this line, but it only serves a helper file from your own computer — no sensitive information is being sent out.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.credential-exfiltration.javascript-secret-to-network in this repository.

Contextual assessment: The scanner reported a credential-to-network match at line 379, but the actual code at that line is `return reply.send(code);` inside the /rewrite-assistant.js GET handler, which serves a local JavaScript file from a path specified by the MARINARA_RWA_PATH environment variable. No credentials are read or exfiltrated. The scan is a false positive.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.credential-exfiltration.javascript-secret-to-network
File role
production
Source
memory-extender/src/setup.ts:379

JavaScript analysis reported javascript.download-to-execution

Expected behavior · high confidence

The extension automatically updates itself by downloading the latest code from your own computer and running it. This is the designed behavior, not a security threat.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The buildLoaderJs function generates a loader script that fetches the extension code from the local sidecar server (127.0.0.1:port) and executes it via a blob script element. This is the project's intended auto-update mechanism, clearly documented in the README. The network retrieval targets only localhost and the execution method (blob URL) is standard for Marinara extensions. No external or malicious network destination is involved.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.download-to-execution
File role
production
Source
memory-extender/src/setup.ts:54-69

OpenGrep reported tavernkeeper.dynamic-execution.node-shell

Expected behavior · high confidence

This code runs a harmless git command to show the version number in the interface. An attacker cannot control what command runs because it is fixed in the code.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.node-shell in this repository.

Contextual assessment: The execSync call runs a hardcoded git command ('git rev-parse --short HEAD') with no user-controlled input. The cwd is validated via existsSync against the repository root, preventing injection. This is used only to derive a build version string for display purposes and is part of the project's legitimate version-reporting functionality.

Impact: none · Exploitability: unlikely

Developer action: None required; the operation is intentional and properly scoped.

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.node-shell
File role
production
Source
memory-extender/src/update.ts:52-56

JavaScript analysis reported javascript.credential-to-network

Expected behavior · high confidence

The extension can store an API key for optional cloud AI access. It only saves the key on your computer and never sends it anywhere unexpected.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.credential-to-network in this repository.

Contextual assessment: The code reads process.env.MARINARA_EXTENDER_API_KEY and saves it to a local .env file. The GET /api/config endpoint returns only a boolean apiKeySet indicator, not the actual key value. The POST /api/config endpoint accepts the API key from the user and writes it to .env for later use with optional external API calls. There is no network exfiltration of the credential; it is only used locally or sent to the user-configured external API endpoint as intended. This is expected behavior for managing an optional external API key.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.credential-to-network
File role
production
Source
memory-extender/src/setup.ts:69-409

JavaScript analysis reported javascript.credential-to-network

Expected behavior · high confidence

The sidecar server includes a feature that lets other tools on your computer use the same AI service connection you set up. It only listens on your own machine and only sends data where you told it to.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.credential-to-network in this repository.

Contextual assessment: The index.ts server registers an OpenAI-compatible inference proxy at /v1/chat/completions that forwards requests to either a local model or an external API using the cached auth token. The credential-to-network flow is the explicit purpose of this route, documented as a convenience proxy so other tools can reuse the same connection config. The server binds to 127.0.0.1, CORS is limited to loopback origins, and the external destination is user-configured. No evidence of unauthorized or covert data transmission.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.credential-to-network
File role
production
Source
memory-extender/src/index.ts:59-234

Credential access and network transmission in one file

Expected behavior · high confidence

The extension makes a request to delete old memory entries from Marinara's own storage. It talks to Marinara's internal API, not to an external server. No credentials are being stolen.

Technical evidence

Scanner reason: A credential source and an outbound network operation were detected in the same file.

Contextual assessment: The scanner correlated credential access and network transmission due to a fetch call at line 4145. The actual code uses a relative URL (/api/lorebooks/...) to delete lorebook entries from Marinara's own backend. This is a legitimate same-origin API call using the user's existing session cookies, not credential exfiltration. The extension manages lorebook entries as part of its memory system feature, and this DELETE call is the expected mechanism to clear old entries before writing new ones.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
tavernkeeper 5
Rule
credential-exfiltration
File role
production
Source
marinara-extender.js:4145

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This line just reads whether the auto-start shortcut exists to show you if it is enabled or not.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: Checks if the autostart file exists to display its status (ON/off) in the interactive console. No persistence action is taken at this line.

Impact: none · Exploitability: unlikely

Developer action: None required; it is a status read-only operation.

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
start.ps1:417

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This line creates a shortcut in your Startup folder so the program runs automatically when you log in. It only happens if you press 'A' to enable it.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: Writes a startup launcher script to the user's Startup folder. This only occurs when the user presses 'A' and the autostart file does not exist. It is an opt-in convenience feature for automatic service start on login.

Impact: none · Exploitability: unlikely

Developer action: None required; the feature is user-consented and clearly documented.

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
start.ps1:478

OpenGrep reported tavernkeeper.credential-exfiltration.javascript-secret-to-network

Expected behavior · high confidence

A security scanner flagged this section, but it only tells your browser whether an API key is already set — it never sends your key anywhere.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.credential-exfiltration.javascript-secret-to-network in this repository.

Contextual assessment: The scanner reported a credential-to-network match at lines 403-410, but those lines are part of the GET /api/config handler which returns configuration values including a boolean apiKeySet indicator (not the actual key). No credential is transmitted over the network. The response contains only configuration metadata, never the secret itself. The scan is a false positive.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.credential-exfiltration.javascript-secret-to-network
File role
production
Source
memory-extender/src/setup.ts:403-410

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This line just prepares a file path for a possible startup shortcut. The shortcut only gets created if the user presses 'A' to enable it, so it is not automatic.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: Line 27 defines a path variable for a potential startup shortcut; no file is created or modified at this line. The actual persistence modification occurs later in an interactive user-command loop (lines 470-483) requiring an explicit key press, making it opt-in and visible to the user.

Impact: none · Exploitability: unlikely

Developer action: None required; the auto-start feature is opt-in and clearly communicated.

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
start.ps1:27

JavaScript analysis reported javascript.credential-to-network

Expected behavior · high confidence

This extension can optionally use an online AI service to analyze roleplay conversations, and it sends the API key you configured to the service you chose. That's exactly what it's supposed to do — there's no hidden behavior.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.credential-to-network in this repository.

Contextual assessment: The ambient.ts module provides LLM-based fact extraction with two paths: a local model (fetch to localUrl) and an optional external API fallback (fetch to externalUpstream with Authorization header from getCachedAuth). The credential-to-network correlation is the intended design for the external fallback path. The server binds to 127.0.0.1, CORS is loopback-restricted, and the external API endpoint is user-configured. No evidence of unexpected destination or exfiltration.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.credential-to-network
File role
production
Source
memory-extender/src/ambient.ts:84-262

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The code sets the address of the extension's own helper server, which runs on your own computer. This is normal and expected for this type of extension.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: Line 22 defines a constant for the sidecar server address, defaulting to the local loopback address 127.0.0.1:3001, with an optional override via window.__meSidecar set by a loader stub. This is a standard pattern for a local service required by the extension's stated purpose: communicating with the Memory Extender sidecar for persistent memory management. No external, user-controlled, or unknown destination is involved; the address is either localhost or explicitly set by the installation loader. The JS-X-Ray 'shady-link' signal is a false positive for this legitimate local-only configuration.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
marinara-extender.js:22

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This line deletes the startup shortcut when you press 'A' to disable auto-start. It only happens if you choose to turn it off.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: Removes the autostart file from the user's Startup folder. This only occurs when the user presses 'A' and the file exists, disabling auto-start. It is part of the user-toggled convenience feature.

Impact: none · Exploitability: unlikely

Developer action: None required; the cleanup is user-initiated.

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
start.ps1:472

OpenGrep reported tavernkeeper.persistence.startup-modification

Expected behavior · high confidence

This line checks if the startup shortcut already exists to know whether to create or remove it when you press 'A'.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.persistence.startup-modification in this repository.

Contextual assessment: Conditional check on autostart file existence as part of the user toggle logic. This decides whether to enable or disable auto-start based on current state and user input.

Impact: none · Exploitability: unlikely

Developer action: None required; it is a necessary state check for a user-controlled feature.

Scanner
opengrep 1.26.0
Rule
tavernkeeper.persistence.startup-modification
File role
production
Source
start.ps1:471

Related contextual observations

Auto-start toggle is user-consented

low risk · high confidence

The program can automatically start with Windows, but only if you press 'A' to enable it. It will never auto-start without your permission.

Technical assessment

The entire auto-start feature (checking, creating, and removing a Startup folder shortcut) is controlled by the user pressing 'A' in an interactive console. No persistence occurs without explicit user action, and the feature is clearly documented as opt-in.

Impact: none · Exploitability: unlikely

Developer action: None required; the implementation is appropriate for a user-controlled convenience feature.

Sources:

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity