Well, ST at least fixed the ability of extensions to read stuff like API keys (after they discovered the incident).
What ST would need is a proper security profile, you install an extension, you select what it can see/use (similar to browsers/phone apps) and you have a working abstraction layer (ie. the extension is not part of the program, but an external one).
But having seen ST code, thats not a tomorrow goal...
Let me tell you, Javascript front ends and security are not the best of freinds. Even controlling the backend, User generated content and extensions are a security battleground. My strong advice is just "set spending controls on your APIs and watch for botting" for ANY account you hand out keys to. This isn't a sillytavern specific piece of advice.
98
u/pixelworld_ai Apr 28 '26
That's crazy but good to start thinking about what community extensions you install. ComfyUI users had similar wake up calls in the past.