TavernKeeper Scan Report

qvink/SillyTavern-MessageSummarize

Commit 81b3326 Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 1 low

What this review found

No material or immediate-danger item was identified.

Expected scanner matches (1)

JavaScript analysis reported javascript.download-to-execution

Expected behavior · low confidence

The supplied excerpt shows an extension that summarizes chat messages and selects configured model connection profiles. It does not show downloaded content being executed or a hidden command being run.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.download-to-execution in this repository.

Contextual assessment: The candidate is based on a broad correlation between network capability and an execution-like sink, but the supplied source context contains configuration and summarization logic only. It shows use of SillyTavern connection profiles for intended model requests, with no demonstrated retrieval-to-execution data flow, destination, trigger, or concealed execution path.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1
Rule
javascript.download-to-execution
File role
production
Source
index.js:282-689

Coverage and limitations

JavaScript coverage

Tools

Limitations

Technical scan identity