# @actions/exec@3.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:10:33.000Z
- Files reviewed: 3
- Findings: 2 medium severity findings
- Report: https://security.togoder.click/npm/@actions/exec
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @actions/exec@3.0.0 on Oct 6, 2026. An AI review of 3 source files produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Command Execution

Finding ID: `NPS-5C1C102612BB`

File: `lib/exec.js:24`

The module exports functions `exec` and `getExecOutput` that execute arbitrary system commands via `ToolRunner`. The `commandLine` parameter is parsed and the first argument is used as the executable path, allowing callers to run any binary with any arguments. While this is expected for a process execution library (like @actions/exec), it represents a powerful capability that could be abused if the package is compromised or if untrusted input is passed.

### [medium] Lack of Input Validation

Finding ID: `NPS-B0E80DA298C3`

File: `lib/exec.js:25`

The `commandLine` parameter is split into arguments without validation or sanitization. Although the documentation states arguments must be correctly escaped, the library itself does not enforce any restrictions, potentially leading to command injection if untrusted input is supplied by consumers.

## Files reviewed

- `lib/exec.js` (medium): The code is a legitimate command execution wrapper (similar to @actions/exec) but exposes process spawning functionality that could be risky if misused or if the package is compromised.
- `lib/interfaces.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/toolrunner.js` (safe): This is the legitimate GitHub Actions toolrunner library; no malicious patterns detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
