# @npmcli/fs@5.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:22:55.000Z
- Files reviewed: 9
- Findings: 1 high, 2 medium severity findings
- Report: https://security.togoder.click/npm/@npmcli/fs
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @npmcli/fs@5.0.0 on Oct 6, 2026. An AI review of 9 source files produced 1 high, 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] File system manipulation outside package scope

Finding ID: `NPS-6F09D70122D1`

File: `lib/move-file.js:10`

The moveFile function recursively moves arbitrary source and destination paths, including symlinks, and ultimately deletes the source with fs.rm(source, { recursive: true, force: true }). This can delete or overwrite files outside the package scope if called with arbitrary paths.

### [medium] Default overwrite enabled

Finding ID: `NPS-7205034EE584`

File: `lib/move-file.js:22`

options.overwrite defaults to true. When overwrite is enabled, destination files are silently replaced, which can lead to data loss.

### [medium] Symlink following/manipulation

Finding ID: `NPS-6D6EB74E30B6`

File: `lib/move-file.js:54`

The code reads symlink targets with fs.readlink and creates symlinks pointing to computed targets. This can be abused to follow symlinks and move/copy files outside intended directories.

## Files reviewed

- `lib/move-file.js` (medium): The code is not overtly malicious, but it performs arbitrary recursive file moves, symlink manipulation, and recursive deletion with overwrite enabled by default, which could be dangerous if exposed to untrusted input.
- `lib/common/get-options.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/common/node.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cp/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cp/index.js` (safe): This is a standard Node.js file system copy utility that delegates to native fs.cp or a local polyfill, with no malicious patterns detected.
- `lib/cp/polyfill.js` (safe): No malicious patterns detected; this is a local filesystem copy polyfill with no network, process execution, or obfuscated code.
- `lib/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/readdir-scoped.js` (safe): No malicious patterns detected; the code only reads directory contents recursively for scoped packages.
- `lib/with-temp-dir.js` (safe): No malicious patterns detected; the code creates and cleans up a temporary directory using standard Node.js APIs.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
