# @typescript-eslint/type-utils@8.70.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:13:25.000Z
- Files reviewed: 22
- Findings: no findings
- Report: https://security.togoder.click/npm/@typescript-eslint/type-utils
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @typescript-eslint/type-utils@8.70.0 on Oct 6, 2026. An AI review of 22 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `dist/TypeOrValueSpecifier.js` (safe): The code is a standard TypeScript ESLint helper module with no malicious patterns, network activity, credential access, or dynamic code execution.
- `dist/builtinSymbolLikes.js` (safe): This is a standard TypeScript helper module from the ts-api-utils/typescript ecosystem with no malicious patterns detected.
- `dist/containsAllTypesByName.js` (safe): No malicious patterns detected
- `dist/discriminateAnyType.js` (safe): No malicious patterns detected
- `dist/getConstrainedTypeAtLocation.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/getContextualType.js` (safe): This file contains TypeScript compiler helper functions for determining contextual types; no malicious patterns, network activity, obfuscation, or suspicious behaviors detected.
- `dist/getDeclaration.js` (safe): No malicious patterns detected
- `dist/getSourceFileOfNode.js` (safe): No malicious patterns detected; the file is a standard TypeScript helper function with esModule interop boilerplate imported from a trusted library (typescript).
- `dist/getTypeName.js` (safe): No malicious patterns detected
- `dist/index.js` (safe): No malicious patterns detected
- `dist/isSymbolFromDefaultLibrary.js` (safe): No malicious patterns detected
- `dist/isTypeBrandedLiteralLike.js` (safe): This file contains only TypeScript compiler helper boilerplate and type-guard logic with no malicious patterns, network access, file system operations, or dynamic code execution.
- `dist/isTypeReadonly.js` (safe): No malicious patterns detected; this is a TypeScript utility function for checking readonly types with only standard dependencies and no network, filesystem, process, or dynamic code execution behavior.
- `dist/isUnsafeAssignment.js` (safe): This is a legitimate TypeScript ESLint utility module with standard helper functions and no malicious patterns.
- `dist/predicates.js` (safe): No malicious patterns detected
- `dist/propertyTypes.js` (safe): No malicious patterns detected; the code is a straightforward TypeScript utility for property type resolution without network, filesystem, process, or dynamic code execution activities.
- `dist/requiresQuoting.js` (safe): No malicious patterns detected; this is a standard TypeScript compiler helper file that only defines identifier quoting logic.
- `dist/typeFlagUtils.js` (safe): No malicious patterns detected; the file contains standard TypeScript compiler helper functions and type flag utilities.
- `dist/typeOrValueSpecifiers/specifierNameMatches.js` (safe): No malicious patterns detected
- `dist/typeOrValueSpecifiers/typeDeclaredInFile.js` (safe): No malicious patterns detected
- `dist/typeOrValueSpecifiers/typeDeclaredInLib.js` (safe): No malicious patterns detected
- `dist/typeOrValueSpecifiers/typeDeclaredInPackageDeclarationFile.js` (safe): No malicious patterns detected; the code is a TypeScript utility for checking type declarations in package declaration files.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
