TavernKeeper Scan Report

bmen25124/SillyTavern-MCP-Client

Commit 04fdfe4 Reviewed

6 material concerns identified.

This advisory report describes what the named tools and contextual reviewer found at one exact commit. Unknown or unobserved behavior may still exist.

0 high 6 material 24 low

What this review found

Dependency advisory GHSA-v39h-62p7-jpjc applies

Material concern · medium confidence

A tool found that one of the project's packages has a serious known security flaw. It is probably in the build tools rather than the extension itself, but serious issues in build tools can still be a problem and should be fixed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v39h-62p7-jpjc to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-v39h-62p7-jpjc) against a declared dependency. The project declares only sillytavern-utils-lib as a production dependency; remaining packages are devDependencies for build and test. The high severity warrants attention even if the affected package is likely a transitive build-time dependency, because supply-chain vulnerabilities in build tooling can compromise build integrity. Specific package identity was not provided, limiting precise impact determination.

Impact: medium · Exploitability: unlikely

Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v39h-62p7-jpjc
File role
production
Source
package-lock.json

Dependency advisory GHSA-q3j6-qgpj-74h6 applies

Material concern · medium confidence

A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed to keep the build process safe.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-q3j6-qgpj-74h6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-q3j6-qgpj-74h6) against a declared dependency. The high severity warrants attention. Without specific package identity, precise runtime versus build-time exposure cannot be confirmed, but the project structure suggests likely build-tooling involvement. High-severity advisories in build tooling can affect build integrity and should be remediated.

Impact: medium · Exploitability: unlikely

Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.

Scanner
osv-scanner 2.4.0
Rule
GHSA-q3j6-qgpj-74h6
File role
production
Source
package-lock.json

Dependency advisory GHSA-wf6x-7x77-mvgw applies

Material concern · medium confidence

A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-wf6x-7x77-mvgw to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-wf6x-7x77-mvgw) against a declared dependency. The high severity warrants attention. The project structure indicates most dependencies are devDependencies for build and test, but without the specific package identity, runtime exposure cannot be fully ruled out. Remediation is recommended.

Impact: medium · Exploitability: unlikely

Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.

Scanner
osv-scanner 2.4.0
Rule
GHSA-wf6x-7x77-mvgw
File role
production
Source
package-lock.json

Dependency advisory GHSA-23c5-xmqv-rm74 applies

Material concern · medium confidence

A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-23c5-xmqv-rm74 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-23c5-xmqv-rm74) against a declared dependency. The high severity warrants attention. The project structure suggests likely build-tooling involvement, but specific package identity was not provided, limiting precise impact determination. High-severity advisories should be remediated regardless of dev versus production classification.

Impact: medium · Exploitability: unlikely

Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.

Scanner
osv-scanner 2.4.0
Rule
GHSA-23c5-xmqv-rm74
File role
production
Source
package-lock.json

Dependency advisory GHSA-3jxr-9vmj-r5cp applies

Material concern · medium confidence

A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3jxr-9vmj-r5cp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-3jxr-9vmj-r5cp) against a declared dependency. The high severity warrants attention. The project structure indicates most dependencies are devDependencies, but without specific package identity, runtime exposure cannot be fully ruled out. Remediation is recommended.

Impact: medium · Exploitability: unlikely

Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3jxr-9vmj-r5cp
File role
production
Source
package-lock.json

Dependency advisory GHSA-v56q-mh7h-f735 applies

Material concern · medium confidence

A tool found a serious known security flaw in one of the project's packages. It is probably in the build tools, but should still be fixed.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v56q-mh7h-f735 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory (GHSA-v56q-mh7h-f735) against a declared dependency. The high severity warrants attention. The project structure suggests likely build-tooling involvement, but specific package identity was not provided. High-severity advisories should be remediated regardless of dev versus production classification.

Impact: medium · Exploitability: unlikely

Developer action: Run npm audit to identify the affected package and update it to a patched version. Prioritize high-severity advisories.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v56q-mh7h-f735
File role
production
Source
package-lock.json

Minor cautions

Dependency advisory GHSA-v6h2-p8h4-qcjw applies

Minor caution · medium confidence

A tool used during development has a known minor security issue. This does not affect the extension that users actually install and run.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v6h2-p8h4-qcjw to a dependency declared by this repository.

Contextual assessment: A known low-severity advisory was matched against a dependency declared in the lockfile. The project's only runtime dependency is sillytavern-utils-lib; all other declared dependencies are devDependencies used for building and testing. The built artifact loaded by SillyTavern is dist/index.js, which is not affected by dev-tooling vulnerabilities. Without the specific package name it is not possible to confirm production exposure, but the project structure strongly suggests this is a dev-dependency issue.

Impact: low · Exploitability: unlikely

Developer action: Update devDependencies to their latest patched versions when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v6h2-p8h4-qcjw
File role
production
Source
package-lock.json

Dependency advisory GHSA-4x5r-pxfx-6jf8 applies

Minor caution · medium confidence

A development tool has a known minor security issue. The extension users install is not affected.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4x5r-pxfx-6jf8 to a dependency declared by this repository.

Contextual assessment: A known low-severity advisory was matched against a dependency in the lockfile. The project declares only sillytavern-utils-lib as a runtime dependency; all other packages are devDependencies for build and test tooling. The shipped extension artifact is the webpack bundle, not the dev toolchain. This is most likely a dev-dependency vulnerability with no production impact.

Impact: low · Exploitability: unlikely

Developer action: Update devDependencies to their latest patched versions when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4x5r-pxfx-6jf8
File role
production
Source
package-lock.json

Dependency advisory GHSA-fv7c-fp4j-7gwp applies

Minor caution · medium confidence

A development or build tool has a known security issue rated high, but it is not part of the extension that users install and run. It mainly matters for the developer's own build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-fv7c-fp4j-7gwp to a dependency declared by this repository.

Contextual assessment: A known high-severity advisory was matched against a dependency in the lockfile. Despite the high scanner severity, the project structure shows only sillytavern-utils-lib as a runtime dependency, with all other packages being devDependencies for build and test. The shipped artifact is the webpack bundle in dist/index.js. High-severity advisories in dev tooling do not directly compromise the runtime extension, though they could affect the build environment if an attacker has access to it.

Impact: low · Exploitability: unlikely

Developer action: Update the affected devDependency to a patched version. If the advisory affects sillytavern-utils-lib or its transitive production dependencies, prioritize the upgrade.

Scanner
osv-scanner 2.4.0
Rule
GHSA-fv7c-fp4j-7gwp
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh29-5h37-fv8m applies

Minor caution · medium confidence

A development tool has a known medium security issue. The extension users install is not directly affected.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh29-5h37-fv8m to a dependency declared by this repository.

Contextual assessment: A known medium-severity advisory was matched against a dependency in the lockfile. The project's runtime dependency surface is limited to sillytavern-utils-lib; all other declared packages are devDependencies. The extension ships a webpack bundle, not the dev toolchain. This is most likely a dev-dependency vulnerability with no direct production impact.

Impact: low · Exploitability: unlikely

Developer action: Update devDependencies to their latest patched versions when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh29-5h37-fv8m
File role
production
Source
package-lock.json

Dependency advisory GHSA-qj8w-gfj5-8c6v applies

Minor caution · medium confidence

A development tool has a known medium security issue. The extension users install is not directly affected.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-qj8w-gfj5-8c6v to a dependency declared by this repository.

Contextual assessment: A known medium-severity advisory was matched against a dependency in the lockfile. The project declares only sillytavern-utils-lib as a runtime dependency; all other packages are devDependencies. The shipped extension is a webpack bundle. This is most likely a dev-dependency vulnerability with no direct production impact.

Impact: low · Exploitability: unlikely

Developer action: Update devDependencies to their latest patched versions when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-qj8w-gfj5-8c6v
File role
production
Source
package-lock.json

Dependency advisory GHSA-5c6j-r48x-rmvq applies

Minor caution · medium confidence

A development or build tool has a known security issue rated high, but it is not part of the extension that users install and run. It mainly matters for the developer's own build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-5c6j-r48x-rmvq to a dependency declared by this repository.

Contextual assessment: A known high-severity advisory was matched against a dependency in the lockfile. The project structure shows only sillytavern-utils-lib as a runtime dependency, with all other packages being devDependencies for build and test. The shipped artifact is the webpack bundle. High-severity advisories in dev tooling do not directly compromise the runtime extension, though they could affect the build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected devDependency to a patched version. If the advisory affects sillytavern-utils-lib or its transitive production dependencies, prioritize the upgrade.

Scanner
osv-scanner 2.4.0
Rule
GHSA-5c6j-r48x-rmvq
File role
production
Source
package-lock.json

Dependency advisory GHSA-v2hh-gcrm-f6hx applies

Minor caution · medium confidence

A development or build tool has a known security issue rated high, but it is not part of the extension that users install and run. It mainly matters for the developer's own build environment.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-v2hh-gcrm-f6hx to a dependency declared by this repository.

Contextual assessment: A known high-severity advisory was matched against a dependency in the lockfile. The project declares only sillytavern-utils-lib as a runtime dependency; all other packages are devDependencies. The shipped extension is a webpack bundle. High-severity advisories in dev tooling do not directly compromise the runtime extension, though they could affect the build environment.

Impact: low · Exploitability: unlikely

Developer action: Update the affected devDependency to a patched version. If the advisory affects sillytavern-utils-lib or its transitive production dependencies, prioritize the upgrade.

Scanner
osv-scanner 2.4.0
Rule
GHSA-v2hh-gcrm-f6hx
File role
production
Source
package-lock.json

Dependency advisory GHSA-968p-4wvh-cqc8 applies

Minor caution · medium confidence

A development tool has a known medium security issue. The extension users install is not directly affected.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-968p-4wvh-cqc8 to a dependency declared by this repository.

Contextual assessment: A known medium-severity advisory was matched against a dependency in the lockfile. The project's runtime dependency surface is limited to sillytavern-utils-lib; all other declared packages are devDependencies. The extension ships a webpack bundle, not the dev toolchain. This is most likely a dev-dependency vulnerability with no direct production impact.

Impact: low · Exploitability: unlikely

Developer action: Update devDependencies to their latest patched versions when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-968p-4wvh-cqc8
File role
production
Source
package-lock.json

Dependency advisory GHSA-2g4f-4pwh-qvx6 applies

Minor caution · medium confidence

A tool found that one of the packages used by this project has a known security issue. It is probably part of the build tools rather than the actual extension users run, so the practical risk is low.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-2g4f-4pwh-qvx6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-2g4f-4pwh-qvx6) against a declared dependency in the lockfile. The project's only production runtime dependency is sillytavern-utils-lib; all other declared dependencies are devDependencies used for build and test tooling. Without the specific package identity it is not possible to confirm runtime exposure, but the project structure suggests this most likely affects build-time tooling rather than the extension code shipped to users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the affected package and update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-2g4f-4pwh-qvx6
File role
production
Source
package-lock.json

Dependency advisory GHSA-h67p-54hq-rp68 applies

Minor caution · medium confidence

A tool found a medium-level security issue in one of the project's packages. It is likely in the build tools and poses low risk to users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-h67p-54hq-rp68 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory (GHSA-h67p-54hq-rp68) against a declared dependency. Given the project structure with predominantly devDependencies, this likely affects build or test tooling. Medium-severity issues in build tooling for a hobbyist extension present low practical risk to end users.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the affected package and update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-h67p-54hq-rp68
File role
production
Source
package-lock.json

Dependency advisory GHSA-7p8r-x3mc-p8w7 applies

Minor caution · medium confidence

A security scanner found that one of the tools used to build this extension has a known security issue. Since this is likely a build-time tool rather than something that runs when you use the extension, it probably does not affect end users directly.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7p8r-x3mc-p8w7 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory against a declared dependency in the lockfile. The project's runtime dependency surface is limited to sillytavern-utils-lib; the remaining declared dependencies are build-time dev tooling (babel, webpack, jest, sass, typescript). Vulnerabilities in dev-only transitive dependencies do not flow into the built extension artifact shipped to end users. Without the specific package name it is not possible to confirm whether this advisory affects a production or dev-only dependency, but the project structure strongly suggests dev tooling exposure.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit or osv-scanner with package details to identify the specific vulnerable package and update it to a fixed version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7p8r-x3mc-p8w7
File role
production
Source
package-lock.json

Dependency advisory GHSA-7r86-cg39-jmmj applies

Minor caution · medium confidence

A security scanner found a known vulnerability in one of the packages listed in this project's dependency lockfile. This is most likely in a development tool and would not affect people using the finished extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-7r86-cg39-jmmj to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a known advisory against a declared dependency in the lockfile. The project declares only one production dependency (sillytavern-utils-lib) with all other packages being dev-only build tooling. Vulnerabilities in dev-only transitive dependencies do not propagate to the built dist/index.js artifact that end users load. The specific package name was not supplied, preventing confirmation of whether this affects a production or dev-only dependency.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific vulnerable package via npm audit and update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-7r86-cg39-jmmj
File role
production
Source
package-lock.json

Dependency advisory GHSA-8fgc-7cc6-rx7x applies

Minor caution · medium confidence

A security scanner found a low-severity known issue in one of this project's dependencies. This is most likely in a development tool and is unlikely to affect users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-8fgc-7cc6-rx7x to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a low-severity known advisory against a declared dependency in the lockfile. The project's dependency tree is dominated by dev-only build tooling. Low-severity advisories in dev tooling transitive dependencies have minimal practical impact on the shipped extension artifact.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific package and update it when convenient.

Scanner
osv-scanner 2.4.0
Rule
GHSA-8fgc-7cc6-rx7x
File role
production
Source
package-lock.json

Dependency advisory GHSA-xvcm-6775-5m9r applies

Minor caution · medium confidence

A security scanner flagged a high-severity vulnerability in a dependency. However, this project uses mostly development tools, so the issue likely affects only the build environment, not the extension that users install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-xvcm-6775-5m9r to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity known advisory against a declared dependency in the lockfile. Despite the scanner severity, the project's production dependency surface is limited to sillytavern-utils-lib, with all other declared packages being dev-only build tooling. If this advisory affects a dev-only transitive dependency, it does not reach the built extension artifact. The specific package name was not supplied, so production-vs-dev classification cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package. If it is a production dependency, prioritize updating immediately; if dev-only, update during routine maintenance.

Scanner
osv-scanner 2.4.0
Rule
GHSA-xvcm-6775-5m9r
File role
production
Source
package-lock.json

Dependency advisory GHSA-3v7f-55p6-f55p applies

Minor caution · medium confidence

A security scanner found a medium-severity issue in one of this project's dependencies. This is most likely in a development tool and would not affect users of the finished extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3v7f-55p6-f55p to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity known advisory against a declared dependency in the lockfile. The project structure indicates the vast majority of dependencies are dev-only build tooling. Medium-severity advisories in dev tooling transitive dependencies do not propagate to the shipped extension artifact.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific package via npm audit and update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3v7f-55p6-f55p
File role
production
Source
package-lock.json

Dependency advisory GHSA-4c8g-83qw-93j6 applies

Minor caution · medium confidence

A security scanner flagged a high-severity vulnerability in a dependency. This project relies mostly on development tools, so the issue likely affects only the build environment rather than the extension users install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-4c8g-83qw-93j6 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity known advisory against a declared dependency in the lockfile. The project declares only sillytavern-utils-lib as a production dependency; all other packages are dev-only build tooling. If this advisory is in a dev-only transitive dependency, it does not affect the built dist artifact. The specific package name was not supplied, preventing definitive production-vs-dev classification.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package. If it is a production dependency, prioritize updating immediately; if dev-only, update during routine maintenance.

Scanner
osv-scanner 2.4.0
Rule
GHSA-4c8g-83qw-93j6
File role
production
Source
package-lock.json

Dependency advisory GHSA-f886-m6hf-6m8v applies

Minor caution · medium confidence

A security scanner found a medium-severity known issue in one of this project's dependencies. This is most likely in a development tool and would not affect users of the extension.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-f886-m6hf-6m8v to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity known advisory against a declared dependency in the lockfile. The project's dependency tree is dominated by dev-only build tooling. Medium-severity advisories in dev tooling transitive dependencies do not reach the shipped extension artifact.

Impact: low · Exploitability: unlikely

Developer action: Identify the specific package via npm audit and update it to a patched version.

Scanner
osv-scanner 2.4.0
Rule
GHSA-f886-m6hf-6m8v
File role
production
Source
package-lock.json

Dependency advisory GHSA-52cp-r559-cp3m applies

Minor caution · medium confidence

A security scanner flagged a high-severity vulnerability in a dependency. This project uses mostly development tools, so the issue likely affects only the build environment, not the extension that users install.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-52cp-r559-cp3m to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity known advisory against a declared dependency in the lockfile. The project declares only one production dependency (sillytavern-utils-lib) with all other packages being dev-only build tooling. If this advisory affects a dev-only transitive dependency, it does not propagate to the built extension artifact. The specific package name was not supplied, so production-vs-dev classification cannot be confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit to identify the specific package. If it is a production dependency, prioritize updating immediately; if dev-only, update during routine maintenance.

Scanner
osv-scanner 2.4.0
Rule
GHSA-52cp-r559-cp3m
File role
production
Source
package-lock.json

Dependency advisory GHSA-3ppc-4f35-3m26 applies

Minor caution · medium confidence

A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-3ppc-4f35-3m26 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project's package.json shows only one production dependency (sillytavern-utils-lib) while all other dependencies are devDependencies used for build, test, and type-checking (babel, webpack, jest, typescript, sass, prettier). Vulnerabilities in build-tool transitive dependencies are generally not reachable at runtime in a SillyTavern client extension. The specific vulnerable package and version were not included in the supplied evidence, preventing confirmation of whether it is a production or dev-only dependency.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. If the vulnerable package is a transitive dev dependency, a devDependency bump or npm override may be needed.

Scanner
osv-scanner 2.4.0
Rule
GHSA-3ppc-4f35-3m26
File role
production
Source
package-lock.json

Dependency advisory GHSA-mh99-v99m-4gvg applies

Minor caution · medium confidence

A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-mh99-v99m-4gvg to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project's dependency tree is dominated by devDependencies for build and test tooling. Without the specific package name and version in the supplied evidence, the vulnerable package cannot be confirmed as production or dev-only, but the project structure strongly suggests these advisories target build-tool transitive dependencies that are not exercised at extension runtime.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. If the vulnerable package is a transitive dev dependency, a devDependency bump or npm override may be needed.

Scanner
osv-scanner 2.4.0
Rule
GHSA-mh99-v99m-4gvg
File role
production
Source
package-lock.json

Dependency advisory GHSA-c2c7-rcm5-vvqj applies

Minor caution · medium confidence

A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-c2c7-rcm5-vvqj to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project declares only sillytavern-utils-lib as a production dependency; all other packages are devDependencies for build and test. The advisory most likely targets a transitive dependency of a build tool. The specific package identity was not provided in the evidence, so production reachability cannot be fully confirmed.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. If the vulnerable package is a transitive dev dependency, a devDependency bump or npm override may be needed.

Scanner
osv-scanner 2.4.0
Rule
GHSA-c2c7-rcm5-vvqj
File role
production
Source
package-lock.json

Dependency advisory GHSA-48c2-rrv3-qjmp applies

Minor caution · medium confidence

A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-48c2-rrv3-qjmp to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a medium-severity advisory against a declared dependency in the lockfile. The project's production dependency surface is limited to sillytavern-utils-lib, with the remainder being build and test devDependencies. A medium-severity advisory in a build-tool transitive dependency is unlikely to be exploitable in the runtime context of a SillyTavern client extension.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-48c2-rrv3-qjmp
File role
production
Source
package-lock.json

Dependency advisory GHSA-38r7-794h-5758 applies

Minor caution · medium confidence

A minor known security issue was found in one of the tools used to build or test this extension. The real-world risk is low. Updating the dependency is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-38r7-794h-5758 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a low-severity advisory against a declared dependency in the lockfile. Low-severity advisories in dependency trees dominated by devDependencies pose minimal runtime risk to a client-side SillyTavern extension. The specific package was not identified in the supplied evidence.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions.

Scanner
osv-scanner 2.4.0
Rule
GHSA-38r7-794h-5758
File role
production
Source
package-lock.json

Dependency advisory GHSA-rgw5-rvv9-x895 applies

Minor caution · medium confidence

A known security issue was found in one of the tools used to build or test this extension. Since these tools mostly run only during development and not when the extension is actually used, the real-world risk is low. Updating the dependency is still good practice.

Technical evidence

Scanner reason: OSV-Scanner matched advisory GHSA-rgw5-rvv9-x895 to a dependency declared by this repository.

Contextual assessment: OSV-Scanner matched a high-severity advisory against a declared dependency in the lockfile. The project's package.json shows only one production dependency while all other packages are devDependencies for build and test tooling. The advisory likely targets a transitive dependency of a build tool. The specific package identity was not provided in the evidence, preventing full confirmation of production reachability.

Impact: low · Exploitability: unlikely

Developer action: Run npm audit and update affected dependencies to patched versions. If the vulnerable package is a transitive dev dependency, a devDependency bump or npm override may be needed.

Scanner
osv-scanner 2.4.0
Rule
GHSA-rgw5-rvv9-x895
File role
production
Source
package-lock.json
Expected scanner matches (0)

None.

Coverage and limitations

Tools

Limitations

Technical scan identity