# @msgpack/msgpack@3.1.3 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T21:17:53.000Z
- Files reviewed: 53
- Findings: no findings
- Report: https://security.togoder.click/npm/@msgpack/msgpack
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @msgpack/msgpack@3.1.3 on Oct 4, 2026. An AI review of 53 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist.cjs/CachedKeyDecoder.cjs` (safe): No malicious patterns detected; the code implements a caching key decoder using only local memory operations.
- `dist.cjs/DecodeError.cjs` (safe): No malicious patterns detected; the code is a simple custom error class with standard prototype chain fix.
- `dist.cjs/Decoder.cjs` (safe): No malicious patterns detected; this is a standard MessagePack decoder implementation with no network, filesystem, process, or credential access.
- `dist.cjs/Encoder.cjs` (safe): No malicious patterns detected; the file is a legitimate MessagePack Encoder implementation from the @msgpack/msgpack library.
- `dist.cjs/ExtData.cjs` (safe): No malicious patterns detected; the file defines a simple ExtData class with no external I/O, code execution, or install-time behavior.
- `dist.cjs/ExtensionCodec.cjs` (safe): Code implements a standard MessagePack ExtensionCodec with no malicious patterns, network activity, file system access, or dynamic code execution.
- `dist.cjs/context.cjs` (safe): No malicious patterns detected
- `dist.cjs/decode.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.cjs/decodeAsync.cjs` (safe): The code is a straightforward async stream decoder wrapper with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
- `dist.cjs/encode.cjs` (safe): No malicious patterns detected
- `dist.cjs/index.cjs` (safe): No malicious patterns detected; the file is a standard module index re-exporting symbols from other local modules.
- `dist.cjs/timestamp.cjs` (safe): No malicious patterns detected
- `dist.cjs/utils/int.cjs` (safe): No malicious patterns detected
- `dist.cjs/utils/prettyByte.cjs` (safe): No malicious patterns detected
- `dist.cjs/utils/stream.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.cjs/utils/typedArrays.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.cjs/utils/utf8.cjs` (safe): The file contains only standard UTF-8 encoding/decoding utilities using TextEncoder/TextDecoder with no network, filesystem, process, or obfuscation concerns.
- `dist.esm/CachedKeyDecoder.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/DecodeError.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/Decoder.mjs` (safe): This is a MessagePack decoder implementation with no malicious patterns detected.
- `dist.esm/Encoder.mjs` (safe): No malicious patterns detected; the code is a standard MessagePack encoder implementation with no network, filesystem, process, or dynamic execution activity.
- `dist.esm/ExtData.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/ExtensionCodec.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/context.mjs` (safe): This is an empty ES module re-export file with only a sourcemap comment, containing no code and no malicious patterns.
- `dist.esm/decode.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/decodeAsync.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/encode.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/index.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/timestamp.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/utils/int.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/utils/prettyByte.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/utils/stream.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/utils/typedArrays.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist.esm/utils/utf8.mjs` (safe): The code implements standard UTF-8 encoding/decoding utilities using TextEncoder/TextDecoder with no network, filesystem, process execution, or obfuscated behavior.
- `dist.umd/msgpack.js` (safe): No malicious patterns detected; this is a legitimate MessagePack serialization library with no network, filesystem, process execution, or credential harvesting behavior.
- `mod.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/CachedKeyDecoder.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/DecodeError.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/Decoder.ts` (safe): This is the standard MessagePack Decoder implementation with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network/file system operations.
- `src/Encoder.ts` (safe): No malicious patterns detected; this is a legitimate MessagePack Encoder implementation with no network, filesystem, process, or dynamic code execution behavior.
- `src/ExtData.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/ExtensionCodec.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/context.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/decode.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/decodeAsync.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/encode.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/timestamp.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/int.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/prettyByte.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/stream.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/typedArrays.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/utf8.ts` (safe): No malicious patterns detected; the code is a standard UTF-8 encoder/decoder implementation with no network, filesystem, process, or dynamic execution activity.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
