TavernKeeper Scan Report

SillyTavern/Extension-CustomSliders

Commit 758aa6f Reviewed

No material or immediate-danger concern was identified in this review.

This advisory report describes what the named tools and review process found at one exact commit. Unknown or unobserved behavior may still exist.

0 immediate danger 0 material 26 low

What this review found

No material or immediate-danger item was identified.

Minor cautions

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.unsafe-regex

Minor caution · medium confidence

A crafted input might briefly slow or freeze the local client, without showing broader security harm.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.unsafe-regex. The match applies to this repository.

Contextual assessment: The expression may permit a local CPU slowdown, but this evidence shows no credential, persistence, code-execution, or cross-user impact.

Impact: low · Exploitability: plausible

Developer action: Bound the input length or replace the expression when practical.

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.unsafe-regex
File role
generated
Source
dist/index.js:1588
Deterministic technical evidence (20)
  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:387ff1385f57b2b03c5ec3e6 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:cc4debc6cb1f2e1673faaa9b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-4c8g-83qw-93j6:pkg:1372faecb5851c2db1a935f0 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:36b5ec528a6a84376d2fa8cc applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-h67p-54hq-rp68:pkg:0199d54d4e55594b20539f39 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-r28c-9q8g-f849:pkg:70fb8de3530fd7e78865a130 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-5p4m-2wfm-xmqj:pkg:a2732cf17ea59b7c9ad7dcba applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-q3j6-qgpj-74h6:pkg:72c95ab6d027fa66d4c2567c applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-qx2v-qp2m-jg93:pkg:e21c031ac1b5a36fba7dab3b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-fxqj-rqcc-2cmp:pkg:38ebb15695df9277a6893d88 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-3jxr-9vmj-r5cp:pkg:57256f4b2ff7d21305eae028 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v39h-62p7-jpjc:pkg:33e1140242e3fdb4577a5fde applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-6g55-p6wh-862q:pkg:1462d68968dddb5a77b9811d applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-rgw5-rvv9-x895:pkg:3a2d891c083fd08457b3fe41 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-52cp-r559-cp3m:pkg:cf5cb3ae8e56cb4261cd5e98 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-7p8r-x3mc-p8w7:pkg:936f2f623c05148e5153dbfe applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-28wg-ghj8-5hjv:pkg:006e2a19c763cc0fc17b9679 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-v2hh-gcrm-f6hx:pkg:65e56d3e94b4e1a92191e9c1 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-2v37-7h3g-55p8:pkg:a9b17cadf83e3a5de547592b applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

  • Dependency advisory GHSA-mh99-v99m-4gvg:pkg:6c65130e708055c34d924f90 applies · osv-scanner 2.4.0

    A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.

    Policy reason: osv-structured-advisory · Execution scope: unknown

    Source: package-lock.json

Contextual expected matches (3)

JavaScript analysis reported javascript.xray.obfuscated-code

Expected behavior · high confidence

The scanner flagged the code as obfuscated, but it is just a standard minified webpack production build. The patterns are normal bundler output, not an attempt to hide malicious code.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.obfuscated-code. The match applies to this repository.

Contextual assessment: The obfuscated-code signal was triggered by the webpack production bundle output in dist/index.js. The supplied context shows standard webpack module patterns: numbered module IDs (208, 314, 601, 72, 659, etc.), webpack runtime helpers (n.d, n.o, n.r, n.n), css-loader and style-loader runtime code for injecting CSS, and the yaml library's visitor/parser classes. Variable minification (single-letter names like e, t, n, s) is expected from webpack's terser minifier in production mode. The code structure is transparent and traceable to known open-source dependencies. No eval with string concatenation, no dynamic code generation from encoded data, no concealed execution paths are present. This is normal minified bundle output, not deliberate obfuscation.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.obfuscated-code
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The scanner flagged repeated link-like text, but the matches are standard YAML library tag identifiers baked into the yaml npm package. There is no network access, data exfiltration, or suspicious communication.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The 51 occurrences flagged by the shady-link rule are YAML standard tag URIs such as tag:yaml.org,2002:map, tag:yaml.org,2002:str, tag:yaml.org,2002:int, etc. These are built-in schema tag constants from the yaml npm library (v2.7.1, declared in package.json). The evidence windows show only YAML parsing/stringifying logic with regex patterns for scalar type resolution. No fetch, XMLHttpRequest, WebSocket, navigator.sendBeacon, or any network API call is present in the supplied context. The tag URIs are string constants used for type identification within the YAML data model, not navigable URLs or network endpoints. This is expected behavior of the yaml dependency bundled by webpack into the extension's dist/index.js.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
generated
Source
dist/index.js:1

JavaScript analysis reported javascript.xray.shady-link

Expected behavior · high confidence

The scanner flagged standard YAML type identifiers that look like web links but are actually just labels defined by the YAML specification. They are used internally by a bundled YAML parser library and do not cause any network activity or pose any security risk.

Technical evidence

Scanner reason: JavaScript analysis matched static JavaScript security signal javascript.xray.shady-link. The match applies to this repository.

Contextual assessment: The scanner's shady-link signal matched 51 occurrences of the string pattern 'tag:yaml.org,2002:' which is the standard YAML tag URI prefix defined by the YAML 1.2 specification. These are not hyperlinks or network destinations; they are type-identifier strings used internally by the bundled 'yaml' npm package (declared as a dependency in package.json at version ^2.7.1) to tag scalar, map, seq, int, float, bool, null, binary, timestamp, and other standard YAML types. The code shown is the minified/bundled YAML parser/serializer library. No fetch, XHR, WebSocket, or other network API calls are present in the evidence. The strings are static constants used for type resolution during YAML parsing and serialization, which matches the project's stated purpose of providing customizable sliders that likely read YAML configuration. There is no data exfiltration, credential access, or external communication.

Impact: none · Exploitability: unlikely

Developer action: none

Scanner
javascript-analysis webcrack-2.16.0_js-x-ray-16.0.0_signatures-1_literals-1_families-1
Rule
javascript.xray.shady-link
File role
generated
Source
dist/index.js:721

Related contextual observations

Bundled YAML library standard tag URIs mistaken for links

low risk · high confidence

The flagged strings are standard YAML type tags from the bundled YAML library, not actual network links.

Technical assessment

The evidence window shows the bundled yaml npm library defining standard YAML schema type tags such as 'tag:yaml.org,2002:str', 'tag:yaml.org,2002:map', 'tag:yaml.org,2002:int', etc. These are specification-defined URIs used as type identifiers within the parser, not network endpoints. The scanner's shady-link rule matched on the URI-like 'tag:' scheme prefix. No network access code is present in the supplied evidence.

Impact: none · Exploitability: unlikely

Developer action: none

Sources:

Coverage and limitations

JavaScript coverage

Unresolved JavaScript stages

Tools

Limitations

Technical scan identity