TavernKeeper Scan Report

vevan/arousalPub

Commit 877a050 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 58 low

What this review found

No material or immediate-danger item was identified.

Deterministic technical evidence (48)
  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/verify-host-build-without-bundled.mjs:29

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-audit.integration.test.ts:33

  • JavaScript analysis reported javascript.xray.short-identifiers · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches.test.ts:1

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/lance-manifest-migrate.test.ts:3

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/ops/backup-data.mjs:122-126

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-api-settings.test.ts:13

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: web/vite.config.ts:11

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/admin/localhost.test.ts:7

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: server/scripts/spike-fts-tokenizers.mjs:7

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-audit.integration.test.ts:4

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/ops/backup-data.mjs:21

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/terminal-link.mjs:22

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches.integration.test.ts:33

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-dev.mjs:47

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/chunk-chain-index-repair.integration.test.ts:33

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-chunks-unreadable.test.ts:34

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: server/scripts/spike-fts-tokenizers.mjs:110

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-prod.mjs:85-94

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-dev.mjs:21

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: server/scripts/spike-fts-tokenizers.mjs:51-55

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/build.mjs:12

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-delete-memory.integration.test.ts:32

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/plugin-lorebook-ensure.test.ts:10

  • JavaScript analysis reported javascript.xray.short-identifiers · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: web/test/utils/composer-slash.test.ts:1

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/chunk-chain-index-repair.integration.test.ts:4

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-delete-memory.integration.test.ts:30

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/dev-config.mjs:35

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: web/scripts/build-analyze.mjs:8-12

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/sync-all-shared.mjs:11

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-server-test-sandbox.mjs:13

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/build-meta.mjs:15-18

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-delete-memory.integration.test.ts:4

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches.integration.test.ts:31

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/run-prod.mjs:84-93

  • JavaScript analysis reported javascript.xray.unsafe-stmt · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/generate-api-error-codes.mjs:9-11

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/regex-rules-file.test.ts:13

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: web/scripts/build-analyze.mjs:5

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/chunk-chain-index-repair.integration.test.ts:31

  • OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval · opengrep 1.26.0

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: owned-inert-tooling · Execution scope: tooling-only

    Source: scripts/generate-api-error-codes.mjs:9-11

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches.integration.test.ts:4

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/plugin-dist.mjs:85

  • JavaScript analysis reported javascript.xray.encoded-literal · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-api-settings.test.ts:20

  • JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/client-ip.test.ts:11

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/watch-plugins.mjs:129

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-chunks-unreadable.test.ts:32

  • JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-branches-audit.integration.test.ts:31

  • JavaScript analysis reported javascript.xray.unsafe-command · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only

    Source: scripts/check-git-eol.mjs:10-13

  • JavaScript analysis reported javascript.xray.data-exfiltration · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1

    This technical signal is not part of the shipped runtime behavior.

    Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data

    Source: server/test/conversation-chunks-unreadable.test.ts:4

Contextual expected matches (9)

JavaScript analysis reported javascript.xray.encoded-literal

Expected behavior · high confidence

This is just a test identifier, not a secret or encoded payload.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.encoded-literal. The match applies to this repository.

Contextual assessment: The literal 'a1b2c3d4' is a test conversation ID used in an integration test file. It has no production impact.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.encoded-literal
File role
production
Source
server/src/integration/conversation-chunks-unreadable-integration.ts:12

Credential access and network transmission in one file

Expected behavior · high confidence

This is just a routine health check for the container's own web service, not a credential theft attempt. The scanner flagged it incorrectly.

Technical evidence

Scanner reason: A credential source and an outbound network operation were detected in the same file.

Contextual assessment: The HEALTHCHECK command fetches the local health endpoint (127.0.0.1) using an environment variable for the port. No credentials are referenced or transmitted in this instruction. The scanner's association of this line with credential exfiltration is a false positive, as the file does not contain any credential source.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
tavernkeeper 5
Rule
credential-exfiltration
File role
production
Source
Dockerfile:47

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

This app runs user-defined regex in a safe mini-environment to avoid crashes, which is a good security practice.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval. The match applies to this repository.

Contextual assessment: The vm.runInNewContext call executes a regex replacement in an isolated sandbox with a timeout. The regex pattern and flags are validated beforehand. This is a deliberate security measure to prevent regex denial-of-service.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
production
Source
server/src/regex-exec-timeout.ts:26-33

Credential access and network transmission in one file

Expected behavior · high confidence

This file syncs settings like lorebook and embedding options with the app's own server. Embedding API keys are sent to that same local server for safe storage and are not kept in the browser or sent anywhere else, which matches how the app says it handles keys.

Technical evidence

Scanner reason: A credential source and an outbound network operation were detected in the same file.

Contextual assessment: This preferences store persists user preferences locally and synchronizes them to the same-origin backend through PATCH requests. The credential-related values are embedding-provider settings: the API key is held transiently in memory, is deliberately not written to localStorage (the persistence routine removes the key storage entry), and when marked dirty it is sent to the same-origin user-preferences endpoint for server-side storage. This matches the project's documented design of keeping provider keys server-side. The flagged fetch transmits only lorebook preference fields and targets the same-origin preferences API. No external or third-party network sink appears in the supplied evidence, and no credential exfiltration data flow is demonstrated.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
tavernkeeper 5
Rule
credential-exfiltration
File role
production
Source
web/src/stores/preferences.ts:700

JavaScript analysis reported javascript.xray.unsafe-regex

Expected behavior · high confidence

This is a routine part of the Handlebars template parser—the regular expressions used to read template code. They are not a security concern.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: Line 1896 contains an array of regular expressions used by the Handlebars lexer for template parsing. These regexes are standard for tokenizing Handlebars syntax (mustache tags, comments, etc.). The scanner flagged 'unsafe-regex' generically, but the supplied code does not demonstrate any ReDoS vulnerability or attacker-controlled input path. The regexes are part of the well-known Handlebars parser library (version 4.7.9) and are not custom or suspicious in this context.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
generated
Source
plugins/trace-keeper/dist/web.mjs:1896

Credential access and network transmission in one file

Expected behavior · high confidence

This file is the app's login and session manager. It saves your session token and sends it only to the app's own server when checking or refreshing your login. Nothing is sent to outside services, so this is normal expected behavior.

Technical evidence

Scanner reason: A credential source and an outbound network operation were detected in the same file.

Contextual assessment: This frontend auth store manages session tokens: it reads and writes access and refresh tokens in localStorage and performs same-origin fetch calls for status checks, session refresh, profile retrieval, login, logout, and device-default updates. All outbound destinations in the supplied evidence are same-origin API endpoints of the same local application; the access token is attached as a Bearer header only to same-origin requests, and the refresh token is sent to the same-origin refresh endpoint. There is no third-party or external network destination, no obfuscated payload, and no disclosure pattern consistent with credential exfiltration. The behavior is proportionate to the file's stated purpose as an authentication store. Storing tokens in localStorage is a common SPA pattern and is XSS-sensitive, but no concrete exposure is demonstrated by this evidence.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
tavernkeeper 5
Rule
credential-exfiltration
File role
production
Source
web/src/stores/auth.ts:127

JavaScript analysis reported javascript.xray.prototype-pollution

Expected behavior · high confidence

This is a false alarm. The code includes the word "__proto__" in a list that controls which properties are allowed—a normal safety feature of the Handlebars template system. No security issue.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.prototype-pollution. The match applies to this repository.

Contextual assessment: Line 589 in the bundled handlebars code sets `propertyWhiteList["__proto__"] = false` as part of Handlebars' internal prototype access control mechanism. This is a defensive whitelist entry, not a prototype pollution exploit. The scanner flagged the literal `__proto__` string, but the code is standard, expected behavior from the Handlebars template engine. No untrusted input or attacker-controlled data flow is involved.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.prototype-pollution
File role
generated
Source
plugins/trace-keeper/dist/web.mjs:589

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The build script checks a special environment variable to decide whether to run tests or skip them. It does not save, copy, or send any environment data anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: Line 41 reads process.env.PLUGIN_WATCH to conditionally skip test execution during watch mode. This is a build-time script; it only reads one environment variable for its own workflow control. It does not serialize, log, or transmit environment contents. The scanner's 'serialize-environment' signal is a false positive for a simple conditional environment check. The script also spawns test processes, but those are local and for testing purposes only.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
plugins/trace-keeper/build.mjs:41

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

This is how the plugin worker knows which code to run, it's part of the app's safety design.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The bootstrap reads a controlled environment variable to locate the plugin module. This is a deliberate part of the plugin sandbox architecture, with network access denied and IPC-only communication.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
server/src/plugin-system/plugin-worker-bootstrap.mjs:105

Related contextual observations

Scanner false positive on HEALTHCHECK

low risk · high confidence

The scanner mistakenly flagged a health check as a credential theft risk, but the health check only pings the app's own URL.

Technical assessment

The scanner rule 'credential-exfiltration' triggered on line 47 but no credential source exists in the provided Dockerfile. The HEALTHCHECK only performs a localhost fetch to verify the app's health endpoint.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity