# @semantic-release/commit-analyzer@13.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:20.000Z
- Files reviewed: 7
- Findings: 3 medium severity findings
- Report: https://security.togoder.click/npm/@semantic-release/commit-analyzer
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @semantic-release/commit-analyzer@13.0.1 on Oct 6, 2026. An AI review of 7 source files produced 3 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading with external input

Finding ID: `NPS-2F266E1AF388`

File: `lib/load-parser-config.js:27`

The code dynamically constructs a module name from the user-supplied 'preset' parameter and imports it from either the package directory or the current working directory. While the dynamic import uses 'import-from-esm' rather than raw 'import()', this pattern allows loading arbitrary npm packages based on external configuration. An attacker controlling the preset value could potentially load a malicious package, though the preset is typically provided by the developer in semantic-release configuration.

### [medium] Dynamic module loading with external input

Finding ID: `NPS-6CFC89CA5893`

File: `lib/load-parser-config.js:30`

The 'config' parameter allows loading an arbitrary npm package name from the current working directory. Similar to the preset case, this enables loading external modules based on configuration. In a supply chain attack scenario where the configuration is controlled by an attacker, this could be exploited to execute malicious code.

### [medium] Dynamic module loading with external input

Finding ID: `NPS-6FC8ABF8B49E`

File: `lib/load-release-rules.js:28`

The function uses importFrom.silent() and importFrom() to dynamically import a module specified by the 'releaseRules' parameter, which can be a string. This allows loading arbitrary modules from the current working directory (cwd) or relative to the script's directory. If an attacker can control the 'releaseRules' configuration, they could load and execute a malicious module. This is a potential vector for code execution if the input is not properly trusted.

## Files reviewed

- `lib/load-parser-config.js` (medium): The code dynamically imports npm packages based on configuration parameters, which is a legitimate feature of semantic-release plugins but presents a moderate risk if configuration is attacker-controlled.
- `lib/load-release-rules.js` (medium): The code dynamically imports external modules based on configuration input, which could lead to arbitrary code execution if the input is untrusted, though no immediate malicious patterns were detected.
- `index.js` (safe): No malicious patterns detected; the code is a standard semantic-release commit analyzer plugin with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `lib/analyze-commit.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/compare-release-types.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/default-release-rules.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/default-release-types.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
