# detect-libc@2.1.2 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:27:31.000Z
- Files reviewed: 4
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/detect-libc
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package detect-libc@2.1.2 on Oct 4, 2026. An AI review of 4 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Spawning processes or shell commands

Finding ID: `NPS-F9B47EFC56C3`

File: `lib/detect-libc.js`

The code uses childProcess.exec and childProcess.execSync to run 'getconf GNU_LIBC_VERSION 2>&1 || true; ldd --version 2>&1 || true' to determine the libc family and version. This is expected behavior for the detect-libc package, which is used to detect the C library on Linux systems. The command is hardcoded and does not take external input, so it is not a security concern.

## Files reviewed

- `lib/detect-libc.js` (safe): The code is safe; it only uses child_process to run a hardcoded command for libc detection, with no malicious patterns detected.
- `lib/elf.js` (safe): The code is a benign ELF interpreter path parser with no malicious patterns detected.
- `lib/filesystem.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/process.js` (safe): The code only reads process platform info and Node.js diagnostic reports locally without any network, process spawning, or file system access.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
