Summary
Togoder Security scanned the npm package env-ci@11.2.0 on Oct 6, 2026. An AI review of 35 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 2
Subprocess execution
NPS-37CBF766127C
The code uses execaSync to run git commands (rev-parse, show) to retrieve repository metadata. This is expected behavior for a library that extracts git information, not a malicious pattern. No user-controlled input is passed to the commands.
Command injection surface
NPS-E8A7B5F5EC7B
The options parameter is forwarded to execaSync, which could theoretically allow a caller to inject environment variables or shell options if untrusted input reaches that parameter. However, this is the caller's responsibility and no malicious payload is present in this file.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | safe | No malicious patterns detected; the code simply detects CI environments by importing and calling service-specific detection/configuration modules. |
| lib/git.js | safe | The file contains only legitimate git metadata extraction utilities using execaSync; no exfiltration, credential harvesting, obfuscation, or other malicious patterns were detected. |
| lib/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| services/appveyor.js | safe | No malicious patterns detected; the code only reads environment variables to expose CI/CD metadata. |
| services/azure-pipelines.js | safe | No malicious patterns detected; the code only reads standard CI environment variables to determine Azure Pipelines configuration. |
| services/bamboo.js | safe | No malicious patterns detected; the code simply reads environment variables to detect Bamboo CI and construct configuration metadata. |
| services/bitbucket.js | safe | No malicious patterns detected; the code only reads standard Bitbucket Pipelines environment variables to produce CI metadata without network, filesystem, or process manipulation. |
| services/bitrise.js | safe | No malicious patterns detected; the code is a benign Bitrise CI environment variable configuration module. |
| services/buddy.js | safe | No malicious patterns detected; the code only reads known Buddy CI environment variables for configuration without any exfiltration, obfuscation, or dangerous operations. |
| services/buildkite.js | safe | No malicious patterns detected; the code only reads Buildkite CI environment variables and returns configuration metadata without any network, filesystem, process, or dynamic code execution behavior. |
| services/circleci.js | safe | No malicious patterns detected |
| services/cirrus.js | safe | The file only reads CI environment variables to build configuration and performs no malicious or suspicious actions. |
| services/cloudflare-pages.js | safe | No malicious patterns detected |
| services/codebuild.js | safe | No malicious patterns detected; the code is a benign CI service detector for AWS CodeBuild that reads environment variables and git metadata without any exfiltration, execution, or credential access. |
| services/codefresh.js | safe | The code simply reads environment variables to detect and configure a CI/CD service (Codefresh) with no malicious behavior detected. |
| services/codeship.js | safe | No malicious patterns detected; the module only reads standard CI environment variables for service detection and configuration. |
| services/drone.js | safe | No malicious patterns detected; the code simply reads environment variables to configure Drone CI integration. |
| services/git.js | safe | No malicious patterns detected in the provided JavaScript file. |
| services/github.js | safe | No malicious patterns detected |
| services/gitlab.js | safe | No malicious patterns detected; the file only reads standard GitLab CI environment variables to configure CI metadata. |
| services/jenkins.js | safe | No malicious patterns detected |
| services/jetbrains-space.js | safe | No malicious patterns detected |
| services/netlify.js | safe | No malicious patterns detected; the code only reads documented Netlify CI environment variables for build metadata. |
| services/puppet.js | safe | No malicious patterns detected |
| services/sail.js | safe | The file only reads standard Sail CI environment variables to detect CI environment and return configuration; no malicious patterns, network calls, filesystem writes, or code execution were found. |
Show 10 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| services/screwdriver.js | safe | No malicious patterns detected; the code only reads CI environment variables to detect and configure Screwdriver.cd CI context. |
| services/scrutinizer.js | safe | This is a benign CI service detection and configuration module that only reads documented Scrutinizer environment variables and returns them, with no network, filesystem, process, or dynamic code execution. |
| services/semaphore.js | safe | The code is a benign CI service detector and configuration parser that reads environment variables and does not exhibit any malicious behavior. |
| services/shippable.js | safe | No malicious patterns detected |
| services/teamcity.js | safe | No malicious patterns detected; the code reads TeamCity build properties and git branch information for CI detection without any exfiltration, credential harvesting, or dynamic code execution. |
| services/travis.js | safe | The file only reads documented Travis CI environment variables to build CI metadata and contains no malicious patterns. |
| services/vela.js | safe | No malicious patterns detected; the file only maps Vela CI environment variables to a configuration object. |
| services/vercel.js | safe | No malicious patterns detected; the code only reads Vercel CI environment variables to return deployment metadata and performs no network, filesystem, or process operations. |
| services/wercker.js | safe | The file is a benign CI/CD environment detector for Wercker that reads standard environment variables without any malicious patterns, network requests, or code execution. |
| services/woodpecker.js | safe | No malicious patterns detected; the code simply reads Woodpecker CI environment variables to report build metadata. |
Scanned versions of env-ci
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 11.2.0 | No issues | 35 | Oct 6, 2026 |
Frequently asked questions
Is env-ci safe to use?
Our AI source review of env-ci@11.2.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does env-ci contain malware?
No malware was identified in env-ci@11.2.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was env-ci checked?
Togoder Security downloaded the published npm package and had an AI model read its 35 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan env-ci together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in env-ci@11.2.0, cost nothing.