Togoder security

npm package security report

@npmcli/agent@4.0.2 security report

Risky patterns found that deserve a look.

Needs review Version 4.0.2 Files reviewed 6 Size 15.9 KB Scanned

Summary

Togoder Security scanned the npm package @npmcli/agent@4.0.2 on Oct 6, 2026. An AI review of 6 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
3
low

Findings 3

low

Dynamic module loading

NPS-6FF34ED1EC83

The module requires several third-party proxy agent packages (http-proxy-agent, https-proxy-agent, socks-proxy-agent) and lru-cache. These are known packages, but the dependency chain should be verified for supply-chain risk since they execute on import.

lib/proxy.js:3
low

Environment variable harvesting

NPS-F82EAE378AC2

The module reads process.env at import time, collecting proxy-related environment variables (https_proxy, http_proxy, proxy, no_proxy). While these are standard proxy config variables, this top-level execution and environment access could be used to silently collect configuration from the host environment.

lib/proxy.js:14
low

Proxy configuration handling

NPS-303A8AFEE346

Proxy URLs (which may contain embedded credentials such as http://user:pass@host) are parsed and used to instantiate agent objects. No direct exfiltration occurs in this file, but proxy credentials are handled and could be logged or leaked by callers.

lib/proxy.js:89

Files reviewed

FileVerdictWhat the reviewer saw
lib/proxy.js medium The file is a proxy configuration utility that reads standard proxy environment variables and manages proxy agents; no active exfiltration, code execution, or backdoor behavior is present, but it does access process.env and handles potentially credential-bearing proxy URLs.
lib/agents.js safe No malicious patterns detected; the code is a legitimate HTTP agent implementation with proxy support, timeout handling, and connection management.
lib/dns.js safe No malicious patterns detected
lib/errors.js safe Cleared by Jev triage; no further analysis needed
lib/index.js safe No malicious patterns detected; the module appears to be a standard HTTP agent/proxy configuration utility.
lib/options.js safe No malicious patterns detected; the file only normalizes and caches network agent options.

Frequently asked questions

Is @npmcli/agent safe to use?

No confirmed malware was found in @npmcli/agent@4.0.2, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.

Does @npmcli/agent contain malware?

No malware was identified in @npmcli/agent@4.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @npmcli/agent checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @npmcli/agent together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @npmcli/agent@4.0.2, cost nothing.

Related security reports