TavernKeeper Scan Report

ZapoVerde/SillyTavern-Triggeryze

Commit 56a1f67 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 13 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

Dependency advisory GHSA-5xrq-8626-4rwp applies

Minor caution · medium confidence

A testing tool used only by developers has a known security issue. It is not part of the extension that users install, so it cannot affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5xrq-8626-4rwp to a dependency declared by this repository.

Contextual assessment: The project's package.json declares only devDependencies (vitest and @vitest/coverage-v8). The lockfile transitive tree is test/build tooling only. The shipped extension consists of index.js and style.css loaded in the SillyTavern client; no node_modules are shipped. The advisory affects a development-only dependency with no runtime reachability in the production extension, so no concrete user harm results.

Impact: none · Exploitability: unlikely

Developer action: Update vitest and @vitest/coverage-v8 to latest versions to refresh the transitive dependency tree and clear the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5xrq-8626-4rwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v6wh-96g9-6wx3 applies

Minor caution · medium confidence

A testing tool used only by developers has a known security issue. It is not part of the extension that users install, so it cannot affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6wh-96g9-6wx3 to a dependency declared by this repository.

Contextual assessment: The project's package.json declares only devDependencies (vitest and @vitest/coverage-v8). The lockfile transitive tree is test/build tooling only. The shipped extension consists of index.js and style.css loaded in the SillyTavern client; no node_modules are shipped. The advisory affects a development-only dependency with no runtime reachability in the production extension, so no concrete user harm results.

Impact: none · Exploitability: unlikely

Developer action: Update vitest and @vitest/coverage-v8 to latest versions to refresh the transitive dependency tree and clear the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6wh-96g9-6wx3
File role
production
Source
package-lock.json

Dependency advisory GHSA-4w7w-66w2-5vf9 applies

Minor caution · medium confidence

A testing tool used only by developers has a known security issue. It is not part of the extension that users install, so it cannot affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4w7w-66w2-5vf9 to a dependency declared by this repository.

Contextual assessment: The project's package.json declares only devDependencies (vitest and @vitest/coverage-v8). The lockfile transitive tree is test/build tooling only. The shipped extension consists of index.js and style.css loaded in the SillyTavern client; no node_modules are shipped. The advisory affects a development-only dependency with no runtime reachability in the production extension, so no concrete user harm results.

Impact: none · Exploitability: unlikely

Developer action: Update vitest and @vitest/coverage-v8 to latest versions to refresh the transitive dependency tree and clear the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4w7w-66w2-5vf9
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Minor caution · medium confidence

A testing tool used only by developers has a known security issue. It is not part of the extension that users install, so it cannot affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: The project's package.json declares only devDependencies (vitest and @vitest/coverage-v8). The lockfile transitive tree is test/build tooling only. The shipped extension consists of index.js and style.css loaded in the SillyTavern client; no node_modules are shipped. The advisory affects a development-only dependency with no runtime reachability in the production extension, so no concrete user harm results.

Impact: none · Exploitability: unlikely

Developer action: Update vitest and @vitest/coverage-v8 to latest versions to refresh the transitive dependency tree and clear the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-67mh-4wv8-2f99 applies

Minor caution · medium confidence

A testing tool used only by developers has a known security issue. It is not part of the extension that users install, so it cannot affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-67mh-4wv8-2f99 to a dependency declared by this repository.

Contextual assessment: The project's package.json declares only devDependencies (vitest and @vitest/coverage-v8). The lockfile transitive tree is test/build tooling only. The shipped extension consists of index.js and style.css loaded in the SillyTavern client; no node_modules are shipped. The advisory affects a development-only dependency with no runtime reachability in the production extension, so no concrete user harm results.

Impact: none · Exploitability: unlikely

Developer action: Update vitest and @vitest/coverage-v8 to latest versions to refresh the transitive dependency tree and clear the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-67mh-4wv8-2f99
File role
production
Source
package-lock.json

Dependency advisory GHSA-r28c-9q8g-f849 applies

Minor caution · medium confidence

A testing tool used only by developers has a known security issue. It is not part of the extension that users install, so it cannot affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-r28c-9q8g-f849 to a dependency declared by this repository.

Contextual assessment: The project's package.json declares only devDependencies (vitest and @vitest/coverage-v8). The lockfile transitive tree is test/build tooling only. The shipped extension consists of index.js and style.css loaded in the SillyTavern client; no node_modules are shipped. The advisory affects a development-only dependency with no runtime reachability in the production extension, so no concrete user harm results.

Impact: none · Exploitability: unlikely

Developer action: Update vitest and @vitest/coverage-v8 to latest versions to refresh the transitive dependency tree and clear the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-r28c-9q8g-f849
File role
production
Source
package-lock.json

Dependency advisory GHSA-fxqj-rqcc-2cmp applies

Minor caution · medium confidence

A testing tool used only by developers has a known security issue. It is not part of the extension that users install, so it cannot affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fxqj-rqcc-2cmp to a dependency declared by this repository.

Contextual assessment: The project's package.json declares only devDependencies (vitest and @vitest/coverage-v8). The lockfile transitive tree is test/build tooling only. The shipped extension consists of index.js and style.css loaded in the SillyTavern client; no node_modules are shipped. The advisory affects a development-only dependency with no runtime reachability in the production extension, so no concrete user harm results.

Impact: none · Exploitability: unlikely

Developer action: Update vitest and @vitest/coverage-v8 to latest versions to refresh the transitive dependency tree and clear the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fxqj-rqcc-2cmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A testing tool used only by developers has a known security issue. It is not part of the extension that users install, so it cannot affect end users.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: The project's package.json declares only devDependencies (vitest and @vitest/coverage-v8). The lockfile transitive tree is test/build tooling only. The shipped extension consists of index.js and style.css loaded in the SillyTavern client; no node_modules are shipped. The advisory affects a development-only dependency with no runtime reachability in the production extension, so no concrete user harm results.

Impact: none · Exploitability: unlikely

Developer action: Update vitest and @vitest/coverage-v8 to latest versions to refresh the transitive dependency tree and clear the advisory.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

This flagged library is only used by the developer's testing tools, not by the extension itself. People who install and run Triggeryze are not exposed to it.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: The project declares only devDependencies (vitest and @vitest/coverage-v8) and ships no runtime npm dependencies; SillyTavern extensions are loaded as static JS/CSS rather than installed npm packages. The matched advisory corresponds to a transitive development-only package used by the test toolchain, so the vulnerable code is not present in the shipped extension and has no runtime reachability for end users. Concrete user harm from the shipped product is not established.

Impact: low · Exploitability: unlikely

Developer action: Update vitest and @vitest/coverage-v8 to patched versions so the development toolchain is no longer flagged.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json

Dependency advisory GHSA-fx2h-pf6j-xcff applies

Minor caution · medium confidence

This flagged library is part of the developer's test setup, not the extension users install. It does not affect people running Triggeryze.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fx2h-pf6j-xcff to a dependency declared by this repository.

Contextual assessment: The lockfile contains only development dependencies for the test runner; the extension manifest loads index.js and style.css directly and declares no runtime dependencies. The advisory matches a development-only transitive package with no path into the shipped extension, so there is no runtime reachability for end users and no demonstrated concrete harm in production.

Impact: low · Exploitability: unlikely

Developer action: Refresh or upgrade the development dependencies to remove the advisory from the lockfile.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fx2h-pf6j-xcff
File role
production
Source
package-lock.json
Expected scanner matches (1)

OpenGrep reported tavernkeeper.dynamic-execution.javascript-eval

Expected behavior · high confidence

The code lets users write simple math expressions inside templates, like adding numbers or using basic math functions. Before running the expression, it checks that only math-related characters are present and blocks everything needed for real code execution, such as letters, quotes, and brackets. This is a normal and safe way to support math in template text.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.dynamic-execution.javascript-eval in this repository.

Contextual assessment: The Function() call at line 320 is inside _evalMath, which evaluates arithmetic expressions from template interpolation. Before the expression reaches Function(), the code substitutes random functions with numeric literals, strips a small allowlist of math function names, and then enforces a strict character allowlist of digits, whitespace, arithmetic operators, parentheses, dots, scientific-notation e/E, ternary and comparison operators, and commas. Letters other than e/E, quotes, brackets, braces, and semicolons are all rejected, preventing property access, string construction, statement chaining, or method invocation. The result is also verified to be a finite number before use. This is a proportionate, well-guarded math evaluator for the project's stated template-interpolation feature.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.dynamic-execution.javascript-eval
File role
production
Source
actions/template.js:320

Related contextual observations

All flagged advisories are in dev-only dependency tree

low risk · high confidence

All eight advisories trace to the development-only dependency tree. The extension ships only static client files, so none of these packages reach end users.

Technical assessment

The root package object in the lockfile shows only devDependencies (vitest and @vitest/coverage-v8). The manifest.json confirms the shipped extension is index.js and style.css with no node_modules. All eight advisories are in the transitive tree of these dev-only tools and have no path to the production extension runtime.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

All declared dependencies are development-only

low risk · medium confidence

The extension does not bundle or install any libraries for end users; the flagged packages exist only for the author's local testing.

Technical assessment

The package.json and lockfile root entry show only devDependencies. The manifest loads the extension via static JS and CSS with no runtime dependency installation, so transitive advisories in the test toolchain do not propagate to the shipped product.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

Tools

Limitations

Technical scan identity