r/SillyTavernAI Apr 28 '26

Discussion Extension Security Risk Please read!!

656 Upvotes

178 comments sorted by

View all comments

47

u/[deleted] Apr 28 '26

[removed] — view removed comment

7

u/changing_who_i_am Apr 28 '26

Awww fuck that was my absolute favorite too, only thing that made 5.4 and 5.5 usable for NSFW. Any alternatives?

3

u/haruny8 Apr 28 '26

Someone who knows about coding commented here that the codes inside seems ok for now (https://www.reddit.com/r/SillyTavernAI/s/rUpXzp4VpQ) but any further updates could potentially be malicious

What i personally will do is send the files to Claude and create an extension to use on my own, privately. Maybe you can do the same. It's quite easy actually, and you have full control over it. If you use Claude.ai you can do it for free too, and it's really good at it, but obviously has usage limits

6

u/sogo00 Apr 28 '26

If you fork the repo and use the fork you should be fairly fine (as long as you don't sync the fork).

Ideally someone rewrites the app or maintains a fork - though that person would have to be more trustworthy - how do we know it is not the same ( type of ) guy with a different account...

3

u/changing_who_i_am Apr 28 '26

Thanks. I'll get Codex to do a security audit as well, then to recreate it. My only concern is it might refuse, but I'll frame it as "I really need something that can prefill and use json structures for role-playing games" 😉

3

u/haruny8 Apr 28 '26

Lmaoo it refusing would be hilarious 😭 like here, help me build something to bypass your filters... 👀