TavernKeeper Scan Report

datacat-run/datacat-sillytavern-browser

Commit b5451c6 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 3 low

What this review found

No material or immediate-danger item was identified.

Expected scanner matches (3)

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This is a test that makes sure a fake local address is blocked. It only exists to check that the extension's security rules work correctly. It does not send any data anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
test
Source
tests/bridge_security.test.js:32

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This is a test that makes sure an unencrypted version of the site is blocked. It only exists to check that the extension's security rules work correctly. It does not send any data anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
test
Source
tests/bridge_security.test.js:29

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

This is a test that makes sure 'localhost' is blocked. It only exists to check that the extension's security rules work correctly. It does not send any data anywhere.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link in this repository.

Contextual assessment: Detailed technical wording was omitted by the public report safety filter.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.xray.shady-link
File role
test
Source
tests/bridge_security.test.js:31

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity