A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
The code is plain and readable, not hidden or scrambled. It does what the README describes: manage character expression sprites. No suspicious behavior was found.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code. The match applies to this repository.
Contextual assessment: The scanner flags an obfuscated-code signal at line 1, but the supplied source is clear, readable, commented JavaScript defining a SillyTavern character-expression extension. No eval, Function constructor, encoded strings, dynamic import, or hidden control flow is present. The extension interacts only with the documented SillyTavern context API and local sprite endpoints, consistent with its stated purpose.