# @scalar/types@0.22.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:06.000Z
- Files reviewed: 40
- Findings: 1 medium, 4 low severity findings
- Report: https://security.togoder.click/npm/@scalar/types
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @scalar/types@0.22.1 on Oct 6, 2026. An AI review of 40 source files produced 1 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading with external input

Finding ID: `NPS-A0863C4A3187`

File: `dist/api-reference/api-reference-configuration.js`

The schema defines a `pluginUrls` option documented as ESM module URLs loaded with dynamic `import()` at runtime. The schema itself only validates these as strings (no allowlist/URL origin validation), meaning untrusted configuration supplied to this library could cause arbitrary external ESM modules to be fetched and executed in the host application context. While this is a documented feature of the Scalar API Reference package rather than an obfuscated backdoor, it constitutes a code-loading primitive driven by potentially external/computed input and is a supply-chain/config-injection risk if configuration is attacker-influenced.

### [low] Overly permissive schema validation (z.custom / z.any)

Finding ID: `NPS-C5264EE34C73`

File: `dist/api-reference/api-reference-configuration.js`

Multiple fields use `z.custom()` or `z.any()` (fetchLikeSchema, hiddenClients, defaultHttpClient, metaData, plugin entries), effectively bypassing validation for functions and arbitrary values. This reduces type-safety guarantees around supplied plugins and customFetch functions, making it harder to bound the behavior of externally supplied configuration that will be executed by the consuming application.

### [low] Deprecated URL auto-rewrite

Finding ID: `NPS-EFB284931B52`

File: `dist/api-reference/api-reference-configuration.js`

The transform silently rewrites `configuration.proxyUrl` from OLD_PROXY_URL to NEW_PROXY_URL at parse time. This redirects requests through a hardcoded external proxy endpoint when the deprecated value is detected, which is a behavioral change to network routing based on configuration; it is documented and intentional, but noteworthy for review.

### [low] External URLs in configuration

Finding ID: `NPS-C108B0706346`

File: `dist/api-reference/base-configuration.js`

The schema defines default external URLs pointing to scalar.com services (dashboard, registry, proxy, api). These are static configuration defaults for the library's intended functionality, not an active data exfiltration mechanism.

### [low] Telemetry enabled by default

Finding ID: `NPS-BAF21D460DCD`

File: `dist/api-reference/base-configuration.js`

The 'telemetry' option defaults to true. While this is a legitimate feature for usage analytics, it does represent data being sent to external servers by default. Users should be aware of this behavior.

## Files reviewed

- `dist/api-reference/api-reference-configuration.js` (medium): The file is a Zod configuration schema for the Scalar API Reference library; no credential harvesting, obfuscation, process spawning, or exfiltration is present, but it declares a `pluginUrls` option that is documented to dynamically import and execute external ESM modules from unvalidated URLs, which is a medium-severity dynamic code-loading risk.
- `dist/api-reference/api-client-plugin.js` (safe): No malicious patterns detected; the file only defines Zod validation schemas for an API client plugin without any executable or exfiltration behavior.
- `dist/api-reference/api-client-translations.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api-reference/api-reference-configuration.test-d.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api-reference/api-reference-plugin.js` (safe): Schema definition file using zod for configuration validation with no network, filesystem, process, or dynamic execution patterns.
- `dist/api-reference/authentication-configuration.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api-reference/authentication-configuration.test-d.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api-reference/base-configuration.js` (safe): No malicious patterns detected; only static configuration schema definitions with default values for a legitimate API reference tool.
- `dist/api-reference/hidden-clients.test-d.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api-reference/html-api.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api-reference/html-rendering-configuration.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api-reference/index.js` (safe): No malicious patterns detected
- `dist/api-reference/source-configuration.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/api-reference/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/asyncapi/3.1/index.generated.js` (safe): No malicious patterns detected
- `dist/asyncapi/3.1/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/entities/index.js` (safe): No malicious patterns detected
- `dist/entities/security-scheme.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/extensions/document/index.js` (safe): No malicious patterns detected
- `dist/extensions/example/index.js` (safe): No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
- `dist/extensions/general/index.js` (safe): No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
- `dist/extensions/index.js` (safe): No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
- `dist/extensions/operation/index.js` (safe): No malicious patterns detected
- `dist/extensions/parameter/index.js` (safe): No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
- `dist/extensions/schema/index.js` (safe): No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
- `dist/extensions/security/index.js` (safe): No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
- `dist/extensions/server/index.js` (safe): No malicious patterns detected
- `dist/extensions/tag/index.js` (safe): No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
- `dist/extensions/workspace/index.js` (safe): No malicious patterns detected; the file is an empty autogenerated ES module with no executable code.
- `dist/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/legacy/index.js` (safe): No malicious patterns detected
- `dist/legacy/reference-config.js` (safe): No malicious patterns detected
- `dist/openapi/3.1/index.generated.js` (safe): No malicious patterns detected
- `dist/openapi/3.1/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/snippetz/index.js` (safe): No malicious patterns detected
- `dist/snippetz/snippetz.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/snippetz/snippetz.test-d.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/index.js` (safe): The file only re-exports a schema from a relative module with no dynamic execution, network, filesystem, or process activity.
- `dist/utils/nanoid.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/utils/utility-types.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
