# env-ci@11.2.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:15:58.000Z
- Files reviewed: 35
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/env-ci
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package env-ci@11.2.0 on Oct 6, 2026. An AI review of 35 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Subprocess execution

Finding ID: `NPS-37CBF766127C`

File: `lib/git.js`

The code uses execaSync to run git commands (rev-parse, show) to retrieve repository metadata. This is expected behavior for a library that extracts git information, not a malicious pattern. No user-controlled input is passed to the commands.

### [low] Command injection surface

Finding ID: `NPS-E8A7B5F5EC7B`

File: `lib/git.js:4`

The `options` parameter is forwarded to execaSync, which could theoretically allow a caller to inject environment variables or shell options if untrusted input reaches that parameter. However, this is the caller's responsibility and no malicious payload is present in this file.

## Files reviewed

- `index.js` (safe): No malicious patterns detected; the code simply detects CI environments by importing and calling service-specific detection/configuration modules.
- `lib/git.js` (safe): The file contains only legitimate git metadata extraction utilities using execaSync; no exfiltration, credential harvesting, obfuscation, or other malicious patterns were detected.
- `lib/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `services/appveyor.js` (safe): No malicious patterns detected; the code only reads environment variables to expose CI/CD metadata.
- `services/azure-pipelines.js` (safe): No malicious patterns detected; the code only reads standard CI environment variables to determine Azure Pipelines configuration.
- `services/bamboo.js` (safe): No malicious patterns detected; the code simply reads environment variables to detect Bamboo CI and construct configuration metadata.
- `services/bitbucket.js` (safe): No malicious patterns detected; the code only reads standard Bitbucket Pipelines environment variables to produce CI metadata without network, filesystem, or process manipulation.
- `services/bitrise.js` (safe): No malicious patterns detected; the code is a benign Bitrise CI environment variable configuration module.
- `services/buddy.js` (safe): No malicious patterns detected; the code only reads known Buddy CI environment variables for configuration without any exfiltration, obfuscation, or dangerous operations.
- `services/buildkite.js` (safe): No malicious patterns detected; the code only reads Buildkite CI environment variables and returns configuration metadata without any network, filesystem, process, or dynamic code execution behavior.
- `services/circleci.js` (safe): No malicious patterns detected
- `services/cirrus.js` (safe): The file only reads CI environment variables to build configuration and performs no malicious or suspicious actions.
- `services/cloudflare-pages.js` (safe): No malicious patterns detected
- `services/codebuild.js` (safe): No malicious patterns detected; the code is a benign CI service detector for AWS CodeBuild that reads environment variables and git metadata without any exfiltration, execution, or credential access.
- `services/codefresh.js` (safe): The code simply reads environment variables to detect and configure a CI/CD service (Codefresh) with no malicious behavior detected.
- `services/codeship.js` (safe): No malicious patterns detected; the module only reads standard CI environment variables for service detection and configuration.
- `services/drone.js` (safe): No malicious patterns detected; the code simply reads environment variables to configure Drone CI integration.
- `services/git.js` (safe): No malicious patterns detected in the provided JavaScript file.
- `services/github.js` (safe): No malicious patterns detected
- `services/gitlab.js` (safe): No malicious patterns detected; the file only reads standard GitLab CI environment variables to configure CI metadata.
- `services/jenkins.js` (safe): No malicious patterns detected
- `services/jetbrains-space.js` (safe): No malicious patterns detected
- `services/netlify.js` (safe): No malicious patterns detected; the code only reads documented Netlify CI environment variables for build metadata.
- `services/puppet.js` (safe): No malicious patterns detected
- `services/sail.js` (safe): The file only reads standard Sail CI environment variables to detect CI environment and return configuration; no malicious patterns, network calls, filesystem writes, or code execution were found.
- `services/screwdriver.js` (safe): No malicious patterns detected; the code only reads CI environment variables to detect and configure Screwdriver.cd CI context.
- `services/scrutinizer.js` (safe): This is a benign CI service detection and configuration module that only reads documented Scrutinizer environment variables and returns them, with no network, filesystem, process, or dynamic code execution.
- `services/semaphore.js` (safe): The code is a benign CI service detector and configuration parser that reads environment variables and does not exhibit any malicious behavior.
- `services/shippable.js` (safe): No malicious patterns detected
- `services/teamcity.js` (safe): No malicious patterns detected; the code reads TeamCity build properties and git branch information for CI detection without any exfiltration, credential harvesting, or dynamic code execution.
- `services/travis.js` (safe): The file only reads documented Travis CI environment variables to build CI metadata and contains no malicious patterns.
- `services/vela.js` (safe): No malicious patterns detected; the file only maps Vela CI environment variables to a configuration object.
- `services/vercel.js` (safe): No malicious patterns detected; the code only reads Vercel CI environment variables to return deployment metadata and performs no network, filesystem, or process operations.
- `services/wercker.js` (safe): The file is a benign CI/CD environment detector for Wercker that reads standard environment variables without any malicious patterns, network requests, or code execution.
- `services/woodpecker.js` (safe): No malicious patterns detected; the code simply reads Woodpecker CI environment variables to report build metadata.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
