TavernKeeper Scan Report

kurohomeless/SillyTavern-Token-and-Cost-Statistics

Commit 2c6b36a Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 2 low

What this review found

No material or immediate-danger item was identified.

Contextual expected matches (1)

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The scanner saw a web address in the code and flagged it. That address is just a standard identifier the browser needs to create SVG graphics for charts. No data is sent anywhere and no network connection is made.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
production
Source
index.js:774

Related contextual observations

Multiple createElementNS calls with standard SVG namespace URI

low risk · high confidence

The repeated SVG namespace string used throughout the chart-drawing function triggered multiple scanner matches. Each occurrence is the same harmless standard identifier needed to create SVG elements for the statistics chart.

Technical assessment

Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity