# cmd-shim@8.0.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:23:07.000Z
- Files reviewed: 2
- Findings: no findings
- Report: https://security.togoder.click/npm/cmd-shim
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package cmd-shim@8.0.0 on Oct 6, 2026. An AI review of 2 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `lib/index.js` (safe): No malicious patterns detected; the code implements standard cmd-shim functionality for generating Windows .cmd and Unix shell wrappers for npm bin scripts.
- `lib/to-batch-syntax.js` (safe): The file contains only pure string transformation utilities that convert shell variable syntax to Windows batch syntax, with no network, filesystem, process execution, or obfuscation patterns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
