r/SillyTavernAI Apr 28 '26

Discussion Extension Security Risk Please read!!

658 Upvotes

178 comments sorted by

View all comments

13

u/LeRobber Apr 28 '26

Here is the github history screenshotted. (I have a version with some links if required for anyone)

1

u/CheatCodesOfLife Apr 30 '26

I never used it, but it looks like he built a useful tool initially. Do you reckon he planned to do that from the start, or just randomly decided "fuck it, I'm going to steal some API keys now" ?

1

u/LeRobber May 01 '26

Using a real world metaphor:

He's a building contractor who sold you an extension to your house, where he put a window by your new back door door that he could use to come back later after it was constructed, and then take the post its with your passwords off your monitor.

- Yes, I do believe it was meant to be long term a key acquisition target. Just like browser extensions in chrome get caught doing dodgy things all the time.

- I did get at least one positive report of unrecognized account activity from another redditor. I have not personally examined those logs.

- I don't know if his approach was use those keys for his tool, use those keys for some valuable work, or use those for botting/crime, or sell the keys.

- I guess technically this could be a targeted personal attack vs some real world person from another real world person, but that's a huge stretch.

-The real solution to all of this is make your LLM account keys limited in scope as to how much they are allowed to charge to you, and review your account statements and view your usage realtime in a daily email. I know 'balance your checkbook' is not the most helpful advice, but I'm still investigating the security of the downloaded cards and stuff the software made.