No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger
0 material
1 low
What this review found
No material or immediate-danger item was identified.
Minor cautions
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
Scanner javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule javascript.xray.unsafe-regex
File role production
Source src/ebook/export/resources.js:30
Coverage and limitations
Inventory 55 files · 595693 bytes
Contextual coverage 1 of 1 candidates assessed
JavaScript coverage
Status Complete
Candidates 45 files · 442737 bytes
X-Ray review families 2 warning occurrences compacted to 1 evidence-preserving review families
Representations 45 raw · 1 decoded · 0 normalized · 0 bundle modules
Stage scans 45 raw signatures · 45 raw AST · 45 raw OpenGrep · 1 derived signatures · 0 derived AST · 1 derived OpenGrep
Tools
Limitations
This advisory review cannot prove the absence of unknown behavior.
Technical scan identity
Full commit ba639959060537a2eb75cc80610f8e8d2ce77e9d
Completed Sep 2, 2026
History depth 1 commit
Method Deterministic evidence with contextual review
Reviewer Not used — deterministic policy
Scanner 0.1.0
Scanner policy 5
Rule catalog 2
Contextual policy 5
Ecosystem context sillytavern-community-v1
Prompt contextual-review-v7
Assessment schema contextual-assessment-v2
Review provenance 0 fresh / 0 reused groups · 0 fresh / 0 reused candidates
Review source reports none
Evidence triage 1 deterministic / 0 contextual candidates · 0 contextual / 1 total behavior cases
Model budget 0 model calls · 0 / 12 fresh cases · 0 / 200000 estimated input · 0 / 250000 actual input · 0 / 40000 output tokens
Review usage 0 input · 0 output · 0 cache read · 0 reasoning tokens
Report 4d631389ab18f21cf4a26c18a3d83b4f9f341950621b87baf84f256882ee740e