TavernKeeper Scan Report

vevan/arousalPub

Commit 185157b Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 58 low

What this review found

No material or immediate-danger item was identified.

Deterministic technical evidence (48)
  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/verify-host-build-without-bundled.mjs:29

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-audit.integration.test.ts:33

  • JavaScript analysis reported javascript.xray.short-identifiers · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches.test.ts:1

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/lance-manifest-migrate.test.ts:3

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/ops/backup-data.mjs:122-126

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-api-settings.test.ts:13

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: web/vite.config.ts:11

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/admin/localhost.test.ts:7

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: server/scripts/spike-fts-tokenizers.mjs:7

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-audit.integration.test.ts:4

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/ops/backup-data.mjs:21

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/terminal-link.mjs:22

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches.integration.test.ts:33

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-dev.mjs:47

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/chunk-chain-index-repair.integration.test.ts:33

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-chunks-unreadable.test.ts:34

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: server/scripts/spike-fts-tokenizers.mjs:110

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-prod.mjs:85-94

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-dev.mjs:21

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: server/scripts/spike-fts-tokenizers.mjs:51-55

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/build.mjs:12

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-delete-memory.integration.test.ts:32

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/plugin-lorebook-ensure.test.ts:10

  • JavaScript analysis reported javascript.xray.short-identifiers · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: web/test/utils/composer-slash.test.ts:1

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/chunk-chain-index-repair.integration.test.ts:4

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-delete-memory.integration.test.ts:30

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/dev-config.mjs:35

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: web/scripts/build-analyze.mjs:8-12

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/sync-all-shared.mjs:11

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-server-test-sandbox.mjs:13

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/build-meta.mjs:15-18

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-delete-memory.integration.test.ts:4

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches.integration.test.ts:31

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-prod.mjs:84-93

  • JavaScript analysis reported javascript.xray.unsafe-stmt · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/generate-api-error-codes.mjs:9-11

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/regex-rules-file.test.ts:13

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: web/scripts/build-analyze.mjs:5

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/chunk-chain-index-repair.integration.test.ts:31

  • OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval · opengrep 1.26.0

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: owned-inert-tooling · Execution scope: tooling-only

    Source: scripts/generate-api-error-codes.mjs:9-11

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches.integration.test.ts:4

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/plugin-dist.mjs:85

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-api-settings.test.ts:20

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/client-ip.test.ts:11

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/watch-plugins.mjs:129

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-chunks-unreadable.test.ts:32

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-audit.integration.test.ts:31

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/check-git-eol.mjs:10-13

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-chunks-unreadable.test.ts:4

Contextual expected matches (9)

JavaScript analysis reported javascript.xray.encoded-literal

Expected behavior · high confidence

The flagged text is just a made-up conversation ID used in a test file. It is a normal test fixture, not a hidden secret or obfuscated code.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.encoded-literal. The match applies to this repository.

Contextual assessment: The flagged literal is a simple test fixture constant CONV_ID set to the string value on line 12. This is an integration test file that creates a temporary conversation index and verifies error handling for missing chunk files. The constant is a hardcoded test identifier, not an encoded secret, credential, or obfuscated payload.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.encoded-literal
File role
production
Source
server/src/integration/conversation-chunks-unreadable-integration.ts:12

Credential access and network transmission in one file

Expected behavior · high confidence

The flagged line is a Docker health check that pings the app's own local health endpoint to see if it is running. It reads the port number from an environment variable and makes a local-only request. No secrets are read or sent anywhere.

Technical evidence

Scanner reason: A credential source and an outbound network operation were detected in the same file.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
tavernkeeper 5
Rule
credential-exfiltration
File role
production
Source
Dockerfile:47

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · medium confidence

The code runs regex operations in a sandboxed environment with a time limit to prevent a malicious or poorly-written regex from freezing the app. The code that runs is fixed by the application, not controllable by users, so this is not a code injection risk.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.

Contextual assessment: The runInNewContext call executes a fixed, static script string that constructs a RegExp from passed parameters and calls text.replace. User-controlled values (pattern, flags, text, replacement) are passed as context data variables, not interpolated into the script string, so there is no arbitrary code injection path. The purpose is to enforce a 250ms timeout on regex execution to prevent ReDoS denial of service, which is a security improvement. While node:vm is not a true security sandbox, it is not being used for isolation here but for its timeout capability, and the executed code is entirely application-controlled.

Impact: low · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
production
Source
server/src/regex-exec-timeout.ts:26-33

Credential access and network transmission in one file

Expected behavior · high confidence

The file saves user settings and sends embedding API key information only to the app's own server, which is the intended design. It deliberately avoids storing raw API keys in the browser. There is no indication of keys being sent to any outside location.

Technical evidence

Scanner reason: A credential source and an outbound network operation were detected in the same file.

Contextual assessment: This preferences store manages embedding API configuration and patches it via fetch to the same-origin relative path /api/user-preferences. The persistEmbeddingLocal function explicitly removes any plaintext API key from localStorage and stores only an apiKeyId reference. The buildEmbeddingServerPatch sends a plaintext apiKey to the app's own backend only when the user has entered a new key and no apiKeyId exists yet, which is the normal key-submission flow. This matches the README's stated design that keys stay on the server and the browser UI never holds plaintext keys. All network calls are same-origin with no external or dynamic destinations and no obfuscation.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
tavernkeeper 5
Rule
credential-exfiltration
File role
production
Source
web/src/stores/preferences.ts:705

JavaScript analysis reported javascript.xray.unsafe-regex

Expected behavior · medium confidence

The flagged patterns are standard parts of common JavaScript libraries (Handlebars template engine and source maps) bundled into this generated file. They are normal parser rules, not a security problem.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The flagged regexes are standard tokenizer rules from the bundled Handlebars lexer and URL-parsing utilities from the source-map library. These are well-known patterns in a generated bundle file. The regexes operate on template and source-map text during normal library operation. No attacker-controlled path to catastrophic backtracking is demonstrated, and the patterns are part of widely used, established dependencies.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
generated
Source
plugins/trace-keeper/dist/web.mjs:1896

Credential access and network transmission in one file

Expected behavior · high confidence

The file manages login tokens and sends them only to the app's own backend server using standard web requests. This is exactly what an authentication module is supposed to do. There is no sign of tokens being sent anywhere unexpected.

Technical evidence

Scanner reason: A credential source and an outbound network operation were detected in the same file.

Contextual assessment: This is a Pinia auth store that reads auth tokens from localStorage and sends them via fetch to same-origin relative API paths (/api/auth/status, /api/auth/refresh, /api/auth/me, /api/auth/login, /api/auth/setup, /api/auth/register, /api/auth/logout, /api/auth/device-default). The token is used as a Bearer header and the refreshToken is sent in a POST body, both to the application's own backend. There is no fetch to any external or third-party destination, no dynamic URL construction, and no obfuscation. The co-location of credential storage and network calls is inherent to any frontend auth store and matches the project's stated authentication purpose.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
tavernkeeper 5
Rule
credential-exfiltration
File role
production
Source
web/src/stores/auth.ts:127

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

The flagged code is from well-known libraries and actually protects against prototype pollution rather than causing it. The references to __proto__ are part of built-in safety checks, not vulnerabilities.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution. The match applies to this repository.

Contextual assessment: The scanner's prototype-pollution signal was triggered by references to __proto__ in bundled third-party code. The first occurrence is Handlebars' proto-access control module, which explicitly sets propertyWhiteList['__proto__'] = false on an object created via Object.create(null) to block prototype-chain access during template rendering. The second occurrence is the source-map library's supportsNullProto feature detection, also using Object.create(null). Both are defensive patterns that mitigate or detect prototype access, not pollution sinks. No attacker-controlled data flows into these assignments.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
plugins/trace-keeper/dist/web.mjs:589

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The build script checks an environment variable to decide whether to run tests after building. This is normal build-tool behavior and does not read or transmit any secrets.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The JS-X-Ray serialize-environment signal was triggered by process.env access at line 41. The code checks process.env.PLUGIN_WATCH to decide whether to skip running tests after an esbuild bundle step. This is a build-time script, not shipped runtime code. It reads a single build-configuration flag with no credential or sensitive value, and there is no network transmission or persistence of environment data.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
plugins/trace-keeper/build.mjs:41

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The code reads a single setting from the environment to know which plugin to load. This is normal configuration, not credential theft. The file actually strengthens security by blocking direct network access from plugins.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The flagged line reads a single environment variable PLUGIN_WORKER_ENTRY_PATH to determine which plugin module to load in the sandboxed worker subprocess. This is a configuration mechanism set by the host process, not serialization or exfiltration of environment variables. The file also implements security hardening: it denies raw network access by replacing fetch and WebSocket, routes all API calls through IPC to the host, and supports Node permission-based filesystem restrictions. Reading one configuration variable for plugin entry path discovery is proportional and expected for a plugin sandbox bootstrap.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
server/src/plugin-system/plugin-worker-bootstrap.mjs:105

Related contextual observations

Bundled Handlebars lexer rules and source-map utilities

low risk · medium confidence

These regexes come from popular third-party libraries included in the bundle. They look complex because parser generators produce them automatically, but they are standard and expected.

Technical assessment

The lexer.rules array and URL regex constants originate from the Handlebars parser generator output and the source-map library, both standard npm dependencies. The complex patterns are characteristic of generated lexers and URL parsers, not hand-crafted obfuscation or ReDoS vectors.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity