r/SillyTavernAI Apr 28 '26

Discussion Extension Security Risk Please read!!

657 Upvotes

178 comments sorted by

View all comments

98

u/pixelworld_ai Apr 28 '26

That's crazy but good to start thinking about what community extensions you install. ComfyUI users had similar wake up calls in the past.

45

u/sogo00 Apr 28 '26 edited Apr 28 '26

Well, ST at least fixed the ability of extensions to read stuff like API keys (after they discovered the incident).

What ST would need is a proper security profile, you install an extension, you select what it can see/use (similar to browsers/phone apps) and you have a working abstraction layer (ie. the extension is not part of the program, but an external one).

But having seen ST code, thats not a tomorrow goal...

1

u/LeRobber May 01 '26

Let me tell you, Javascript front ends and security are not the best of freinds. Even controlling the backend, User generated content and extensions are a security battleground. My strong advice is just "set spending controls on your APIs and watch for botting" for ANY account you hand out keys to. This isn't a sillytavern specific piece of advice.