TavernKeeper Scan Report

vadash/Extension-Summaryception

Commit cadb34a Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 46 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
src/core/snippet-metadata.js:6

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
src/core/structural-headers.js:3

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
production
Source
src/core/summarizer-state.js:10
Deterministic technical evidence (36)
  • Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:02e3933277d4b322a1bb7329 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-frvp-7c67-39w9:pkg:682033ccbfda6cc7860c37a3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/lint.yml:13

  • zizmor reported unpinned-uses · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/lint.yml:15

  • Dependency advisory GHSA-jqff-g426-hqxp:pkg:854a0d49497d146572e51ae0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:bcb01fa3f22fe943388f7142 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-f65p-4m7j-42xc:pkg:606d0d5ceca35425ecc15653 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:821253a22c3d87a034daa956 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-22jq-vg5j-6vgg:pkg:9eb93abfae910113d9babee3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:3f058ee2b68aac4f6bcbbf9e applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-8j4g-w8fx-2239:pkg:a083f0089a00b08c85dd5ef3 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:2c6a626dc52bd9af79c86b60 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-c83g-rgw3-j3cx:pkg:515b9115544de0ef0bef6c23 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r292-9mhp-454m:pkg:0e2bbe9034aea9bae7981dcd applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:590275f7f1e65a0bda08b540 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5jgf-p345-68v8:pkg:1c914207f2e972385868dc00 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:f395337a0cb5249680cc1cad applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-f23p-vx2j-j53r:pkg:9eaf75fff76c34730a920a16 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • zizmor reported excessive-permissions · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/lint.yml:10-23

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:4a6bce6b1ed4b848fe37e071 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • zizmor reported artipacked · zizmor 1.28.0

    The code has a known weakness, though this scan does not show that anyone can exploit it here.

    Policy reason: zizmor-known-workflow-rule · Execution scope: automation

    Source: .github/workflows/lint.yml:13

  • Dependency advisory GHSA-54fx-42gc-7vw4:pkg:01213c09920e558b257a5c07 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-x5fp-wj9c-mxmx:pkg:705f9f71274a97ab9614e3a9 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:6ce644699a81459598ff3ec1 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4xrf-jv44-h6hh:pkg:249ffb00fffad7006fcf485a applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:d055453f026a4e70572d800d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4mjr-xmp4-gh2g:pkg:403639b5d67091c3ba3cd2e1 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:48f7fae3c8c125b98852d2a2 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:97b607f316e1d58c10e4e4eb applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fph4-wmhf-6fwf:pkg:806f4cd5acb08ce901fc0fde applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-73wf-gq98-2v4g:pkg:ef11510aa22fea15604e276b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-79qm-7rj5-m7r9:pkg:9da158dae724299c9774def1 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mwp4-54f8-5fhr:pkg:dbb007cbd7ab30b0c5bafbe0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:33bd75a43666b34e8d957c42 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:17a4bca76c8dccd42bb43bfa applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:c15eeb4b6498ad284f4ce31d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

Contextual expected matches (7)

OpenGrep reported tavernkeeper.download-and-execute.shell-pipeline

Expected behavior · high confidence

The flagged line is just instructions in a help document, telling developers how to install a separate issue-tracking helper that the project's maintainers use. The roleplay extension never runs this command, and it never runs on its own; a person would have to manually copy it and choose to run it. There is no hidden activity here.

Technical evidence

Scanner reason: OpenGrep matched static-analysis rule tavernkeeper.download-and-execute.shell-pipeline. The match applies to this repository.

Contextual assessment: The match is a fenced shell example inside a developer documentation file that introduces the third-party issue-tracking tool this repository uses for its own workflow. The flagged line is that external tool's standard install instruction, shown in a marked code block with plain commentary. Nothing in the repository executes it: the file is inert documentation, extension installation and runtime never invoke it, and no code path reads it. Execution would require a developer to deliberately copy the command out of the documentation and run it, at which point the trust decision concerns the documented third-party project rather than this extension. The pattern is fully disclosed and unobfuscated, so the scanner hit is candidate-locating evidence only, not demonstrated behavior of the shipped extension.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
opengrep 1.26.0
Rule
tavernkeeper.download-and-execute.shell-pipeline
File role
documentation
Source
.beads/README.md:64-65

JavaScript analysis reported javascript.xray.data-exfiltration

Expected behavior · high confidence

A static scanner flagged a common file-handling import, but the actual script only rebuilds some local code bundles on the maintainer's computer after each commit. It never sends anything over the network.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.data-exfiltration. The match applies to this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.data-exfiltration
File role
production
Source
.husky/post-commit-repomix.js:3

Gitleaks reported vault-service-token

Expected behavior · high confidence

The scanner saw the word token in the name of a setting that controls how many summary tokens to keep, and mistook the name for a leaked password. The flagged line only resets that budget number back to its default value. No password, key, or login credential is present anywhere in the shown code, and nothing is sent anywhere.

Technical evidence

Scanner reason: Gitleaks matched secret-detection rule vault-service-token. The match applies to this repository.

Contextual assessment: The flagged line is part of a confirm-guarded settings-reset routine that copies numeric token-budget defaults from the extension's defaults object into its own settings object, then saves and refreshes the UI. The property name contains the word token, which most plausibly triggered the vault-service-token pattern, but the supplied source at and around the flagged line contains no credential literal, no authentication identifier, and no secret value. There is no data flow to any external destination: the assignment writes only to in-memory extension settings that are persisted locally. Vault service tokens are infrastructure credentials used to authenticate to a secrets server, and nothing in this file or its imports contacts such a service. The surrounding handlers (export, import, clear memory, force summarize, template restore) all match the extension's stated purpose of layered chat summarization and are user-initiated with confirmation prompts. Scanner severity and rule name are candidate-locating evidence only; the actual code shows a false-positive keyword match on benign budget-setting names.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
gitleaks 8.30.1
Rule
vault-service-token
File role
production
Source
src/entry/ui-events.js:741

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

The script hands its own settings to helper programs it starts on the same computer, which is normal and necessary for them to work. Nothing is collected, stored, or sent anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The flagged occurrence forwards the existing environment object to locally spawned child processes running repository-defined bundle commands. Passing the environment is required behavior for spawning the package manager, and the children run on the same machine with captured output written only to the local terminal on failure. The environment is not serialized to persistent storage, embedded in committed artifacts, or transmitted to any remote destination, so the credential-theft category implied by the signal is not supported by any data flow in the supplied source. This is routine child-process usage in developer tooling.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
.husky/post-commit-repomix.js:69

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

This is a pre-commit helper that runs quality checks on the developer's own machine. It reads one optional setting and passes its environment to the local tools it starts, which is standard practice. Nothing is sent anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The two flagged occurrences are a configuration read of one environment variable controlling error-output length, and forwarding of the environment object to locally spawned tooling processes in a developer pre-commit hook. The hook runs type checking, formatting, lint staging, and tests on the maintainer's machine before a commit, staging formatter output in the local repository. All child processes are local, output is written to the terminal with truncation, and there is no network egress or persistence beyond the local repository. Environment contents are never transmitted, logged, or embedded in committed artifacts, so the credential-theft category implied by the static signal has no supporting data flow.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
.husky/pre-commit.js:6

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

A scanner flagged normal handling of environment settings in a developer's push-time checks. The script only runs local lint and formatting checks and prints the results; nothing leaves the machine.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The two flagged occurrences are a configuration read of one environment variable controlling error-output truncation, and forwarding of the environment object to locally spawned package-manager processes in a developer pre-push hook that mirrors continuous-integration lint and format checks. All spawned processes run locally with captured output, results print to the terminal, and the source contains no network requests, remote destinations, or writes outside the development machine. The environment is passed to same-machine child processes required for the checks to function and is never serialized into committed output or transmitted, so the credential-theft category implied by the signal is unsupported by the actual data flow.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
production
Source
.husky/pre-push.js:9

JavaScript analysis reported javascript.xray.serialize-environment

Expected behavior · high confidence

This helper automatically updates the project's version numbers and makes a local commit. The flagged environment handling is the normal way to pass settings to the local programs it starts. Nothing is collected or sent anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.serialize-environment. The match applies to this repository.

Contextual assessment: The two flagged occurrences are a guard read of a skip-flag environment variable and a merge of the current environment with a small override when spawning local revision-control child processes. The tooling script increments the version field in local manifest files and creates an automatic local commit, with recursion prevented by the skip flag and a commit-subject pattern check. All spawned processes are local, the environment is only forwarded to same-machine children, and there is no network activity, remote destination, or transmission of environment contents. The credential-theft category implied by the static signal is not supported by any data flow in the supplied source.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.serialize-environment
File role
tooling
Source
scripts/bump-version-after-commit.js:17

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity