No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger
0 material
3 low
What this review found
No material or immediate-danger item was identified.
Minor cautions
JavaScript analysis reported javascript.xray.unsafe-regex
Minor caution · medium confidence
A crafted input might briefly slow or freeze the local client, without showing broader security harm.
Technical evidence
Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.
Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.
Impact: low · Exploitability: plausible
Developer action: Bound the input length or replace the expression when practical.
Scanner javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule javascript.xray.unsafe-regex
File role production
Source lib/repair-engine.js:7
Deterministic technical evidence (2)
JavaScript analysis reported javascript.xray.obfuscated-code · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-content · Execution scope: test-documentation-data
Source: test/repair-engine.test.js:1
JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason: javascript-xray-inert-tooling · Execution scope: tooling-only
Source: scripts/smoke-live.mjs:2
Coverage and limitations
Inventory 9 files · 97350 bytes
Contextual coverage 3 of 3 candidates assessed
JavaScript coverage
Status Incomplete
Candidates 4 files · 87288 bytes
X-Ray review families 5 warning occurrences compacted to 3 evidence-preserving review families
Representations 4 raw · 1 decoded · 0 normalized · 0 bundle modules
Stage scans 4 raw signatures · 4 raw AST · 3 raw OpenGrep · 1 derived signatures · 0 derived AST · 1 derived OpenGrep
Unresolved JavaScript stages lib/repair-engine.js — raw-opengrep / parse
Tools
Limitations
This advisory review cannot prove the absence of unknown behavior. JavaScript analysis was incomplete, so this first-filter scan supports no clean conclusion about unobserved behavior.
Technical scan identity
Full commit 00ac549cabae583f7d02e23569103d734093916f
Completed Aug 26, 2026
History depth 8 commits
Method Deterministic evidence with contextual review
Reviewer Not used — deterministic policy
Scanner 0.1.0
Scanner policy 5
Rule catalog 2
Contextual policy 5
Ecosystem context sillytavern-community-v1
Prompt contextual-review-v7
Assessment schema contextual-assessment-v2
Review provenance 0 fresh / 0 reused groups · 0 fresh / 0 reused candidates
Review source reports none
Evidence triage 3 deterministic / 0 contextual candidates · 0 contextual / 3 total behavior cases
Model budget 0 model calls · 0 / 12 fresh cases · 0 / 200000 estimated input · 0 / 250000 actual input · 0 / 40000 output tokens
Review usage 0 input · 0 output · 0 cache read · 0 reasoning tokens
Report cf9768add1243b045de7771996d163267ef71fcf42d0beca6b40eb674cb9bf8a