Togoder security

npm package security report

env-ci npm package: is it safe?

No malicious code found.

No issues Version 11.2.0 Files reviewed 35 Size 27.3 KB Scanned

Summary

Togoder Security scanned the npm package env-ci@11.2.0 on Oct 6, 2026. An AI review of 35 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
2
low

Findings 2

low

Subprocess execution

NPS-37CBF766127C

The code uses execaSync to run git commands (rev-parse, show) to retrieve repository metadata. This is expected behavior for a library that extracts git information, not a malicious pattern. No user-controlled input is passed to the commands.

lib/git.js
low

Command injection surface

NPS-E8A7B5F5EC7B

The options parameter is forwarded to execaSync, which could theoretically allow a caller to inject environment variables or shell options if untrusted input reaches that parameter. However, this is the caller's responsibility and no malicious payload is present in this file.

lib/git.js:4

Files reviewed

FileVerdictWhat the reviewer saw
index.js safe No malicious patterns detected; the code simply detects CI environments by importing and calling service-specific detection/configuration modules.
lib/git.js safe The file contains only legitimate git metadata extraction utilities using execaSync; no exfiltration, credential harvesting, obfuscation, or other malicious patterns were detected.
lib/utils.js safe Cleared by Jev triage; no further analysis needed
services/appveyor.js safe No malicious patterns detected; the code only reads environment variables to expose CI/CD metadata.
services/azure-pipelines.js safe No malicious patterns detected; the code only reads standard CI environment variables to determine Azure Pipelines configuration.
services/bamboo.js safe No malicious patterns detected; the code simply reads environment variables to detect Bamboo CI and construct configuration metadata.
services/bitbucket.js safe No malicious patterns detected; the code only reads standard Bitbucket Pipelines environment variables to produce CI metadata without network, filesystem, or process manipulation.
services/bitrise.js safe No malicious patterns detected; the code is a benign Bitrise CI environment variable configuration module.
services/buddy.js safe No malicious patterns detected; the code only reads known Buddy CI environment variables for configuration without any exfiltration, obfuscation, or dangerous operations.
services/buildkite.js safe No malicious patterns detected; the code only reads Buildkite CI environment variables and returns configuration metadata without any network, filesystem, process, or dynamic code execution behavior.
services/circleci.js safe No malicious patterns detected
services/cirrus.js safe The file only reads CI environment variables to build configuration and performs no malicious or suspicious actions.
services/cloudflare-pages.js safe No malicious patterns detected
services/codebuild.js safe No malicious patterns detected; the code is a benign CI service detector for AWS CodeBuild that reads environment variables and git metadata without any exfiltration, execution, or credential access.
services/codefresh.js safe The code simply reads environment variables to detect and configure a CI/CD service (Codefresh) with no malicious behavior detected.
services/codeship.js safe No malicious patterns detected; the module only reads standard CI environment variables for service detection and configuration.
services/drone.js safe No malicious patterns detected; the code simply reads environment variables to configure Drone CI integration.
services/git.js safe No malicious patterns detected in the provided JavaScript file.
services/github.js safe No malicious patterns detected
services/gitlab.js safe No malicious patterns detected; the file only reads standard GitLab CI environment variables to configure CI metadata.
services/jenkins.js safe No malicious patterns detected
services/jetbrains-space.js safe No malicious patterns detected
services/netlify.js safe No malicious patterns detected; the code only reads documented Netlify CI environment variables for build metadata.
services/puppet.js safe No malicious patterns detected
services/sail.js safe The file only reads standard Sail CI environment variables to detect CI environment and return configuration; no malicious patterns, network calls, filesystem writes, or code execution were found.
Show 10 more files
FileVerdictWhat the reviewer saw
services/screwdriver.js safe No malicious patterns detected; the code only reads CI environment variables to detect and configure Screwdriver.cd CI context.
services/scrutinizer.js safe This is a benign CI service detection and configuration module that only reads documented Scrutinizer environment variables and returns them, with no network, filesystem, process, or dynamic code execution.
services/semaphore.js safe The code is a benign CI service detector and configuration parser that reads environment variables and does not exhibit any malicious behavior.
services/shippable.js safe No malicious patterns detected
services/teamcity.js safe No malicious patterns detected; the code reads TeamCity build properties and git branch information for CI detection without any exfiltration, credential harvesting, or dynamic code execution.
services/travis.js safe The file only reads documented Travis CI environment variables to build CI metadata and contains no malicious patterns.
services/vela.js safe No malicious patterns detected; the file only maps Vela CI environment variables to a configuration object.
services/vercel.js safe No malicious patterns detected; the code only reads Vercel CI environment variables to return deployment metadata and performs no network, filesystem, or process operations.
services/wercker.js safe The file is a benign CI/CD environment detector for Wercker that reads standard environment variables without any malicious patterns, network requests, or code execution.
services/woodpecker.js safe No malicious patterns detected; the code simply reads Woodpecker CI environment variables to report build metadata.

Scanned versions of env-ci

VersionVerdictFilesScanned
11.2.0 No issues 35 Oct 6, 2026

Frequently asked questions

Is env-ci safe to use?

Our AI source review of env-ci@11.2.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does env-ci contain malware?

No malware was identified in env-ci@11.2.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was env-ci checked?

Togoder Security downloaded the published npm package and had an AI model read its 35 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan env-ci together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in env-ci@11.2.0, cost nothing.

Related security reports