TavernKeeper Scan Report

vadash/Extension-Summaryception

Commit 189ced1 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 45 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
src/core/snippet-metadata.js:6

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
src/core/structural-headers.js:3

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
src/core/summarizer-state.js:10
Deterministic technical evidence (28)
  • Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:02e3933277d4b322a1bb7329 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-frvp-7c67-39w9:pkg:682033ccbfda6cc7860c37a3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/lint.yml:13

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/lint.yml:15

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:bcb01fa3f22fe943388f7142 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:821253a22c3d87a034daa956 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-22jq-vg5j-6vgg:pkg:9eb93abfae910113d9babee3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:3f058ee2b68aac4f6bcbbf9e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8j4g-w8fx-2239:pkg:a083f0089a00b08c85dd5ef3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:2c6a626dc52bd9af79c86b60 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r292-9mhp-454m:pkg:0e2bbe9034aea9bae7981dcd applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:590275f7f1e65a0bda08b540 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:f395337a0cb5249680cc1cad applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-f23p-vx2j-j53r:pkg:9eaf75fff76c34730a920a16 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • zizmor reported excessive-permissions · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/lint.yml:10-23

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:4a6bce6b1ed4b848fe37e071 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • zizmor reported artipacked · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/lint.yml:13

  • Dependency advisory GHSA-54fx-42gc-7vw4:pkg:01213c09920e558b257a5c07 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:6ce644699a81459598ff3ec1 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4xrf-jv44-h6hh:pkg:249ffb00fffad7006fcf485a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-79qm-7rj5-m7r9:pkg:9da158dae724299c9774def1 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mwp4-54f8-5fhr:pkg:dbb007cbd7ab30b0c5bafbe0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:33bd75a43666b34e8d957c42 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

Contextual expected matches (9)

OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline

Expected behavior · high confidence

The flagged line is just documentation showing how to install a separate issue-tracking tool. It is not part of the extension's code and does not run when the extension is used.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.

Contextual assessment: The OpenGrep download-and-execute rule matched a curl-pipe-bash install command in a markdown code block within .beads/README.md. This file is documentation for the Beads issue-tracking tool, not executable code in the Summaryception extension. The install command is a standard pattern used by many CLI tools and only appears as example instructions in a README. The file role is documentation, execution scope is unknown, and this content is never executed by the extension at runtime. There is no code path from the extension to this command.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.download-and-execute.shell-pipeline
File role
documentation
Source
.beads/README.md:64-65

JavaScript analysis reported javascript.xray.data-exfiltration

Expected behavior · high confidence

Detailed wording was omitted by the public report safety filter.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.data-exfiltration. The match applies to this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.data-exfiltration
File role
production
Source
.husky/post-commit-repomix.js:3

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

A developer git hook passes the local environment to child processes so npm scripts can run correctly. This is standard Node.js practice and does not exfiltrate any data.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The JS-X-Ray serialize-environment signal triggered on line 69, which is the `encoding: 'utf8'` property within the execFileSync options object for runRepomix. The nearby `env: process.env` on line 70 passes the environment to child processes executing npm run commands (repomix:source-full, etc.). This is standard practice for Node.js child process execution — the environment must be inherited for npm scripts to function. No environment variables are serialized to external destinations, logged, or transmitted over the network. The hook operates entirely locally as a post-commit git hook.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
.husky/post-commit-repomix.js:69

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

A developer git hook passes the local environment to child processes so linting and tests can run. This is standard practice and does not steal or transmit any data.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The JS-X-Ray serialize-environment signal triggered on line 6, with 2 occurrences. The two uses of process.env are: line 7 (`process.env.PRECOMMIT_ERROR_LINES` for a configurable tail-line count) and line 46 (`env: process.env` passed to execFileSync for running npm scripts). This is a standard Husky pre-commit hook that runs tsc, prettier, lint-staged, and tests. Passing process.env to child processes is required for npm scripts to function. No environment variables are serialized to external destinations, logged to remote services, or transmitted over the network. All operations are local build-tooling.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
.husky/pre-commit.js:6

Gitleaks reported vault-service-token

Expected behavior · high confidence

The scanner flagged a line containing the word 'token' in a variable name about token budgets, but no actual secret exists. The code simply resets a configuration value to its default.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule vault-service-token. The match applies to this repository.

Contextual assessment: The gitleaks vault-service-token rule matched on line 754, which contains `s.layer0SummaryTokenTarget = defaultSettings.layer0SummaryTokenTarget;`. This is a settings-reset assignment in the onResetDefaults function. The matched pattern is a false positive triggered by the variable name containing 'token' (referring to LLM token budgets, not credentials). No secret value is present in the source, no network call is made, and the line only copies a default numeric setting. The explanation confirms the matched value was removed, indicating no real credential was found.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
vault-service-token
File role
production
Source
src/entry/ui-events.js:754

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

A developer git hook passes the local environment to child processes so lint and format checks can run. This is standard practice and does not steal or transmit any data.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The JS-X-Ray serialize-environment signal triggered on line 9, with 2 occurrences. The two uses of process.env are: line 10 (`process.env.PREPUSH_ERROR_LINES` for configurable output tail lines) and line 49 (`env: process.env` passed to execFileSync for running npm lint and format:check scripts). This is a standard Husky pre-push hook that mirrors CI lint and format checks. Passing process.env to child processes is required for npm scripts to function correctly. No environment variables are serialized to external destinations, logged remotely, or transmitted over the network. All operations are local development tooling.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
.husky/pre-push.js:9

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

This is a build helper script that automatically bumps version numbers after commits. It passes the current environment variables to git so git can work properly. This is normal and expected for a local build tool. No data is sent anywhere unusual.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The scanner flagged line 17 where process.env is spread into the child process environment object: env: { ...process.env, ...options.env }. This is standard practice for passing environment variables to a child_process.execFileSync call. The script is a build tooling file (bump-version-after-commit.js) that runs git commands locally to automate version bumping. Spreading process.env is necessary to preserve PATH and other git configuration. There is no exfiltration, network transmission, or obfuscation. The environment is passed to a local git process, not to a remote destination. No secrets are selectively extracted, logged, or sent elsewhere. This is expected behavior for a local development tool.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
scripts/bump-version-after-commit.js:17

Gitleaks reported vault-service-token

Expected behavior · high confidence

The scanner saw the word 'token' in a settings property name and flagged it as a possible secret. In reality this is just a configuration setting that controls how many tokens the summarizer should target. It has nothing to do with passwords or API keys.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule vault-service-token. The match applies to this repository.

Contextual assessment: The gitleaks scanner flagged line 759 with a vault-service-token rule. Line 759 contains: s.layer0SummaryTokenTarget = defaultSettings.layer0SummaryTokenTarget;. This is a settings reset assignment for a token-count target configuration value, not an actual credential or secret. The matched text is a property name containing the word 'token' in the context of token-count budgeting for summarization, not an authentication credential. There is no real secret exposed in the source code. The scanner pattern matched a false positive on a configuration property name related to LLM token counting budgets.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
vault-service-token
File role
production
Source
src/entry/ui-events.js:759

JavaScript analysis reported javascript.xray.unsafe-import

Expected behavior · high confidence

The extension loads a built-in SillyTavern module (the regex engine) using a fixed, hardcoded path. This is how SillyTavern extensions are supposed to access host application features. The path is not influenced by any user input or external data, so there is no security risk.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-import. The match applies to this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-import
File role
production
Source
src/foundation/context.js:263

Related contextual observations

Settings reset line falsely matched as credential

low risk · high confidence

The flagged line is part of a settings reset function that restores default token budget values — entirely normal for a configuration-heavy extension.

Technical assessment

Line 754 assigns defaultSettings.layer0SummaryTokenTarget to the settings object during the onResetDefaults function. This is standard configuration management for a SillyTavern extension that manages token budgets for summarization. No credential material is involved.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Documentation-only install command for third-party tool

low risk · high confidence

A README for the Beads issue tracker includes a standard curl install command. This is documentation only and poses no risk to extension users.

Technical assessment

The matched content is a bash install snippet inside a markdown code fence in .beads/README.md. This is a documentation file describing the Beads tool, unrelated to the extension's runtime behavior. The curl-pipe-bash pattern is a common install method documented in many open-source projects. No executable code in the extension references or invokes this command.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Local git hook uses standard Node.js fs and env patterns

low risk · high confidence

This is a standard developer git hook that refreshes local code bundles after commits. It only runs on the developer's machine and does not transmit data anywhere.

Technical assessment

The post-commit-repomix hook uses fs for local file tracking (temp file for last HEAD), process.env for child process inheritance, and execFileSync to run npm scripts locally. All operations are confined to the local repository and temp directory. No network calls or external data transmission exists in the code.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Standard pre-commit hook uses process.env for child process execution

low risk · high confidence

This pre-commit hook runs type checking, formatting, linting, and tests locally. It uses the environment only to configure and execute these standard build steps.

Technical assessment

The pre-commit hook reads process.env.PRECOMMIT_ERROR_LINES for output formatting and passes process.env to execFileSync when running tsc, prettier, lint-staged, and npm test. These are standard local development tooling commands. No data is exfiltrated or sent to external endpoints.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Standard pre-push hook uses process.env for child process execution

low risk · high confidence

This pre-push hook runs lint and format checks locally before pushing. It uses the environment only to configure and execute these standard checks.

Technical assessment

The pre-push hook reads process.env.PREPUSH_ERROR_LINES for output formatting and passes process.env to execFileSync when running npm run lint and npm run format:check. These are standard local development tooling commands that mirror CI checks. No data is exfiltrated or sent to external endpoints.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity