# @npmcli/git@7.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:00.000Z
- Files reviewed: 13
- Findings: 3 medium, 8 low severity findings
- Report: https://security.togoder.click/npm/@npmcli/git
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @npmcli/git@7.0.2 on Oct 6, 2026. An AI review of 13 source files produced 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Spawning processes or shell commands

Finding ID: `NPS-80874DE42816`

File: `lib/is-clean.js:1`

The code imports './spawn.js' and calls it with arguments to run a command (likely 'git status --porcelain=v1 -uno'). While the arguments appear hardcoded, the imported spawn module could execute arbitrary shell commands or have side effects. This is a common pattern for executing external processes, which can be abused if the spawn module is malicious or if the arguments are influenced by external input (here they are static).

### [medium] Security-relevant behavior modification

Finding ID: `NPS-6794B6A8F20D`

File: `lib/opts.js:50`

Sets GIT_SSH_COMMAND to 'ssh -oStrictHostKeyChecking=accept-new' and GIT_ASKPASS to 'echo' by default. This silently disables SSH host key verification and supplies a no-op askpass, weakening the end-user's SSH security posture without explicit consent.

### [medium] Process / child_process spawning

Finding ID: `NPS-44027F202070`

File: `lib/opts.js:50`

The default GIT_SSH_COMMAND configures ssh to be spawned by git. Combined with GIT_ASKPASS='echo', this changes how external processes are executed on behalf of the user, though the module itself does not directly spawn processes.

### [low] Spawn processes

Finding ID: `NPS-B8407499A834`

File: `lib/clone.js`

The code spawns git subprocesses (clone, fetch, checkout, init, remote, submodule, rev-parse) via a spawn utility. This is expected for a package manager's git cloning functionality and arguments are constructed from package metadata (repo, ref, revDoc.rawRef), not from arbitrary untrusted user input.

### [low] Network requests

Finding ID: `NPS-ACCAC79ED8A1`

File: `lib/clone.js`

Git commands make network requests to the repository URL provided in package metadata. This is inherent to the package's purpose (cloning git repositories) and not exfiltration of local data.

### [low] File system manipulation

Finding ID: `NPS-5AF40F6A941E`

File: `lib/clone.js`

Creates directories, initializes git repositories, and writes files within the specified target directory (derived from repo name and cwd). Operations are scoped to the intended clone target.

### [low] Environment / Config Harvesting

Finding ID: `NPS-832D57319159`

File: `lib/opts.js:5`

Reads the user's ~/.gitconfig file and inspects core.sshCommand and core.askpass settings, plus GIT_SSH_COMMAND and GIT_ASKPASS environment variables. While only boolean presence is checked, it is still reading user credentials-adjacent configuration data outside the package scope.

### [low] Top-level code execution on import

Finding ID: `NPS-C3BDBC5CEB42`

File: `lib/opts.js:44`

The module executes file system reads (loadGitConfig → fs.readFileSync on ~/.gitconfig) and environment reads at import time, and computes finalGitEnv using those values. This side-effecting behavior runs whenever the module is required.

### [low] Dynamic module loading inside function

Finding ID: `NPS-D00B31259F4C`

File: `lib/spawn.js:8`

require('./which.js') is executed lazily at call time rather than at module load. This is an unusual pattern but not inherently malicious; it could be used to defer resolution, though no external/computed path is used.

### [low] Spawning processes

Finding ID: `NPS-06D527F10FA8`

File: `lib/spawn.js:19`

The module wraps git command execution via @npmcli/promise-spawn, spawning child processes with user-controllable arguments (gitArgs). This is expected for a git utility package, but in a malicious context it could be abused to execute arbitrary commands.

### [low] Retry logic on failures

Finding ID: `NPS-64DC911160D7`

File: `lib/spawn.js:34`

The promiseRetry wrapper retries failed git commands up to a configurable number of times. While normal for network operations, uncontrolled retries with attacker-supplied opts could amplify certain requests.

## Files reviewed

- `lib/is-clean.js` (medium): The file spawns a child process via a local spawn module, which could be a vector for command execution, though no obvious malicious intent is present in this snippet alone.
- `lib/opts.js` (medium): The module reads ~/.gitconfig and git-related environment variables and, without user opt-in, weakens SSH host key checking via GIT_SSH_COMMAND and disables credential prompting via GIT_ASKPASS; no exfiltration or code execution red flags, but it degrades security posture and runs logic at import time.
- `lib/spawn.js` (medium): The file is a legitimate git-spawning helper with no clear exfiltration, credential harvesting, obfuscation, or backdoor patterns, though it does spawn subprocesses and lazily requires a local module.
- `lib/clone.js` (safe): The code is a legitimate git cloning utility from npm's pacote library; it spawns git commands and performs filesystem/network operations as expected for its function, with no malicious patterns detected.
- `lib/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/find.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index.js` (safe): No malicious patterns detected; the file is a simple module aggregator that re-exports sibling modules with no executable, network, or obfuscated code.
- `lib/is.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/lines-to-revs.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/make-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/revs.js` (safe): No malicious patterns detected; the code performs a legitimate git ls-remote call with caching and no data exfiltration or suspicious behavior.
- `lib/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/which.js` (safe): No malicious patterns detected; the module only resolves the git binary path via the 'which' package and returns it or an error.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
