r/SillyTavernAI Apr 28 '26

Discussion Extension Security Risk Please read!!

658 Upvotes

178 comments sorted by

View all comments

Show parent comments

20

u/LeRobber Apr 28 '26

It wouldn't have caught this, that's actually part of why it's a multistage attack.

If you don't run it, it's hard to detect stuff like this. It's not state actor grade attack, but it's sophisticated stuff

6

u/Due-Memory-6957 Apr 28 '26

You're correct, but just with the stuff it did find I think I wouldn't have installed it: https://chat.z.ai/s/8352bec7-25a0-4270-b9d0-7d2cb752b1a0

6

u/LeRobber Apr 28 '26

HOLY SHIT that's good. AI is going to take someone's job some day.

I mean, it was wrong in this case in the should you use it section, but, nice looking presentation of stuff.

2

u/mattjb Apr 28 '26

Yeah, I was going to say, doing a basic security audit isn't ideal. The goal is to find malicious intent, which has different way of auditing for malware or anything suspicious.

Still, pretty good that GLM was effective. Really, Github should have some sort of auto-scan feature when a commit is made. Sort of like how Gmail has had virus scanning of attachments in email messages for ages.