TavernKeeper Scan Report
0cyris/SillyTavern-AskPlayer
Commit 1993a0b Reviewed
No material or immediate-danger concern was identified in this review.
This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.
0 immediate danger 0 material 8 low
What this review found
No material or immediate-danger item was identified.
Deterministic technical evidence (8)
-
zizmor reported template-injection · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
JavaScript analysis reported javascript.xray.serialize-environment · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-content· Execution scope: test-documentation-dataSource: test/browser/serve.mjs:22
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
JavaScript analysis reported javascript.xray.shady-link · javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
This technical signal is not part of the shipped runtime behavior.
Policy reason:
javascript-xray-inert-content· Execution scope: test-documentation-dataSource: test/browser/serve.mjs:64
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
zizmor reported template-injection · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
zizmor reported template-injection · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation -
zizmor reported template-injection · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason:
zizmor-known-workflow-rule· Execution scope: automation
Coverage and limitations
JavaScript coverage
Tools
- inventory 0.1.0 — completed
- tavernkeeper-static 5 — completed
- gitleaks 8.30.1 — completed
- opengrep 1.26.0 — completed
- javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1 — completed
- osv-scanner 2.4.0 — completed
- zizmor 1.28.0 — completed
- malcontent 1.25.7 — not-applicable
Limitations
- This advisory review cannot prove the absence of unknown behavior.