# eslint@10.12.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:16.000Z
- Files reviewed: 410
- Findings: 6 medium, 18 low severity findings
- Report: https://security.togoder.click/npm/eslint
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package eslint@10.12.0 on Oct 6, 2026. An AI review of 410 source files produced 6 medium, 18 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading with computed path

Finding ID: `NPS-B02E79D7B94E`

File: `bin/eslint.js:113`

getErrorMessage() dynamically constructs a require() path using error.messageTemplate (`require(`../messages/${error.messageTemplate}.js`)`). While messageTemplate is typically controlled internally by ESLint, if an attacker can influence error.messageTemplate (e.g., via a third-party plugin throwing a crafted error), this could enable arbitrary module resolution/loading within the parent directory. This is a potential vector for loading unintended modules.

### [medium] Dynamic code execution via data URL module

Finding ID: `NPS-8A86341F5F45`

File: `lib/cli.js:78`

The createOptionsModule function constructs a JavaScript module source string by embedding serialized CLI options via JSON.stringify and imports it through a base64-encoded data:text/javascript URL. While the input is JSON-encoded (mitigating direct injection), dynamically generating and loading executable module code from user-controlled CLI options is a code-generation pattern that can be abused and is difficult to audit. A malicious or crafted option value that survives JSON serialization into the template could alter the module body.

### [medium] Spawning external process

Finding ID: `NPS-1AD7502F2C38`

File: `lib/cli.js:348`

The inspect-config code path uses require('cross-spawn') and spawn.sync('npx', ['@eslint/config-inspector@latest', ...flags]) with stdio: 'inherit'. This downloads and executes an unpinned, externally-hosted npm package (@latest) at runtime, which is a supply-chain risk: the fetched package is not integrity-verified and could change or be compromised at any time. The flags are derived from resolved config file paths.

### [medium] Dynamic import

Finding ID: `NPS-9525054BDA66`

File: `lib/eslint/eslint.js`

The loadFormatter method dynamically imports arbitrary formatter modules. While this is a legitimate feature of ESLint, it could be abused to load malicious code if a user is tricked into using a malicious formatter name. The formatter path is resolved based on user input and could potentially point to an attacker-controlled module or file path.

### [medium] Dynamic module loading

Finding ID: `NPS-FB3827E3E825`

File: `lib/eslint/eslint.js`

The fromOptionsModule method loads options from a module URL. This allows dynamic loading of JavaScript modules based on a URL, which could be exploited if an attacker can control the URL, leading to arbitrary code execution.

### [medium] Dynamic module loading with computed input

Finding ID: `NPS-57A44A1D7019`

File: `lib/eslint/worker.js:70`

The worker dynamically loads an ESLint options module from a URL or path provided via workerData (loadOptionsFromModule(eslintOptionsOrURL)). If this value is controllable by an attacker (e.g., through CLI options or shared workerData), it could lead to loading and executing arbitrary JavaScript. This is a legitimate feature of ESLint's multithreaded worker design, but it still represents a code-loading vector that should be treated as a potential risk if untrusted input can reach it.

### [low] Spawning external processes

Finding ID: `NPS-22C8701C5888`

File: `bin/eslint.js:88`

spawnExternalCommand() uses cross-spawn to execute external commands (`npm init @eslint/config@latest` and `npx @eslint/mcp@latest`). These are triggered when the user passes `--init` or `--mcp`. This is expected behavior for ESLint's CLI migration path, but it does fetch and execute remote packages from the npm registry, which introduces supply-chain risk (e.g., if `@eslint/config` or `@eslint/mcp` were compromised). Note that the commands are hard-coded, not derived from user input, mitigating injection concerns.

### [low] File system write outside package scope

Finding ID: `NPS-CF8FCBAB879F`

File: `lib/cli.js:111`

printResults resolves the user-supplied outputFile against process.cwd(), creates directories with mkdir(..., { recursive: true }), and writes the formatter output there. The destination is controlled by CLI input and can target arbitrary filesystem locations outside the package directory.

### [low] Dynamic module loading with computed input

Finding ID: `NPS-C684F89B8B66`

File: `lib/cli.js:492`

ESLint.fromOptionsModule(optionsURL) is invoked with a computed URL derived from user-supplied CLI options. Dynamic module loading based on runtime-constructed URLs expands the attack surface for arbitrary module resolution.

### [low] Dynamic import

Finding ID: `NPS-550E11E95089`

File: `lib/config/config-loader.js:249`

The code uses dynamic import() to load JavaScript configuration files (eslint.config.js) from paths resolved from user input. This is a required, documented behavior of ESLint, not an exfiltration or backdoor. The imported files are the user's own config files, not external or attacker-controlled remote modules.

### [low] Require cache manipulation

Finding ID: `NPS-46F27EE218B9`

File: `lib/config/config-loader.js:265`

The code deletes entries from require.cache to force re-import of config files when their mtime changes. This is intentional for hot-reloading user config and is scoped to the config file path only, with no broad cache poisoning.

### [low] Dependency loading

Finding ID: `NPS-7FB46858A023`

File: `lib/config/config-loader.js:400`

The static loadJiti method dynamically imports the 'jiti' package at runtime. This is a declared optional dependency for TypeScript config support, not an undeclared or obfuscated module load.

### [low] Dynamic import with computed input

Finding ID: `NPS-D79D14D342D1`

File: `lib/eslint/eslint-helpers.js`

The `loadOptionsFromModule` function and the `import('@humanfs/node')` call use dynamic imports. However, `loadOptionsFromModule` is designed to load a user-specified ESLint options module (a documented feature), and the `@humanfs/node` import is a fixed, trusted package dependency. There is no evidence of malicious intent.

### [low] Environment variable access

Finding ID: `NPS-F5418CBA526D`

File: `lib/eslint/eslint-helpers.js`

`mergeEnvironmentFlags` reads the `ESLINT_FLAGS` environment variable. This is a documented ESLint feature for supplying CLI flags and does not involve credential harvesting or exfiltration.

### [low] File system manipulation

Finding ID: `NPS-7F00898BBA14`

File: `lib/eslint/eslint.js`

The code writes files (output fixes) and deletes cache files. While these are expected behaviors for a linter, they involve file system operations outside the immediate package scope (writing to user-specified paths). This is standard for ESLint but could be misused if paths are attacker-controlled.

### [low] Worker threads

Finding ID: `NPS-25F7E5F14009`

File: `lib/eslint/eslint.js`

The code spawns worker threads to lint files. This is a legitimate performance feature. However, it uses SHARE_ENV which shares the environment variables with workers, potentially exposing environment variables to worker threads. This is not malicious by itself but could be a concern if workers are compromised.

### [low] Runtime compilation cache enablement

Finding ID: `NPS-4356F1C79B0E`

File: `lib/eslint/worker.js:13`

The worker calls require("node:module").enableCompileCache?.() at load time. This is a Node.js API that caches compiled bytecode on disk for subsequent runs. While not inherently malicious, it writes cached V8 code to the filesystem outside the normal linting scope and executes at worker import time. It could be abused to cache or replay compiled code if paths were attacker-controlled, though here it uses default cache directories.

### [low] File Read from Configurable Path

Finding ID: `NPS-7675D37CFFF7`

File: `lib/services/suppressions-service.js:193`

The load() method reads from this.filePath which is set by the caller. No path traversal from untrusted input is present; the path comes from ESLint's configuration.

### [low] File Write to Configurable Path

Finding ID: `NPS-EA690EB152F1`

File: `lib/services/suppressions-service.js:219`

The save() method writes to this.filePath, which is passed in via constructor options. This is normal for a suppressions file manager (ESLint's official suppressions feature) and the path is controlled by the calling code, not external input.

### [low] Spawning processes or shell commands

Finding ID: `NPS-87C9A6629AB6`

File: `lib/shared/runtime-info.js`

The code uses cross-spawn.sync to execute external commands ('npm --version', 'npm ls ...', 'npm bin -g'). This is a process spawning pattern. Although cross-spawn is a well-known library and the arguments are static, executing external binaries at runtime can be a security concern if the PATH or environment is manipulated. In this context it appears legitimate for gathering environment info (the code is from ESLint and clearly documented as such).

### [low] Environment information gathering

Finding ID: `NPS-4FB994F555DF`

File: `lib/shared/runtime-info.js`

The module collects environment details including Node version, npm version, local/global ESLint versions, and OS platform/release. This is expected behavior for a CLI diagnostic utility, but it does read execution environment information. It does not read sensitive files (no .npmrc, .ssh, etc.) and does not send data externally.

### [low] JSON.parse of external command output

Finding ID: `NPS-1040F99B2B62`

File: `lib/shared/runtime-info.js`

The result of `npm ls --depth=0 --json` is parsed with JSON.parse. While not a direct vulnerability, parsing untrusted command output is a pattern to note. The parsed output is only used to extract version strings.

### [low] Dynamic module loading

Finding ID: `NPS-1687BB209989`

File: `lib/shared/translate-cli-options.js:41`

The code uses ModuleImporter to dynamically import ESLint plugins and parsers based on CLI-supplied names (via the --plugin and --parser options). While this is expected and intended behavior for ESLint, it allows loading and executing arbitrary modules from the filesystem or node_modules if an attacker controls CLI arguments. This is not malicious per se, but is a code execution vector if untrusted input reaches these options.

### [low] Dynamic module loading

Finding ID: `NPS-84D9024F8DA3`

File: `lib/shared/translate-cli-options.js:166`

The parser option is passed directly to importer.import(), which resolves and executes an arbitrary module specified by the user. This is a normal ESLint feature but represents dynamic code loading driven by external input.

## Files reviewed

- `bin/eslint.js` (medium): This is the official ESLint CLI entrypoint; no exfiltration, credential harvesting, obfuscation, or backdoor patterns were detected, but it does dynamically require modules based on error templates and spawns npm/npx to fetch and run external packages via --init/--mcp flags.
- `lib/cli.js` (medium): This is the legitimate ESLint CLI entry point; it contains no data exfiltration, credential harvesting, or obfuscated payloads, but does exhibit a few low-to-medium risk patterns (data-URL module generation from CLI options, unpinned npx @latest subprocess spawn, and user-controlled output file writes) that are typical of a real linter CLI rather than overt malware.
- `lib/eslint/eslint.js` (medium): The code contains legitimate dynamic imports and file system operations typical of a linter, but these features could be abused if inputs are not properly sanitized, posing a medium risk.
- `lib/eslint/worker.js` (medium): This appears to be a legitimate ESLint worker thread with no clear malicious patterns, but it contains dynamic module loading from worker-provided input and enables compile cache at import time, which are worth noting as potential risk surfaces if untrusted data can reach them.
- `lib/shared/runtime-info.js` (medium): This appears to be legitimate ESLint environment-info utility code that spawns npm commands to gather version data, with no clear malicious exfiltration, credential harvesting, obfuscation, or backdoor patterns.
- `lib/shared/translate-cli-options.js` (medium): This is legitimate ESLint CLI option translation code with no malicious patterns; it uses dynamic imports for plugins/parsers as an intended feature, not a backdoor.
- `conf/ecma-version.js` (safe): Cleared by Jev triage; no further analysis needed
- `conf/globals.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/api.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cli-engine/formatters/html.js` (safe): No malicious patterns detected; this is a legitimate ESLint HTML formatter that properly escapes user-controlled data and performs no network, filesystem, or process operations.
- `lib/cli-engine/formatters/json-with-metadata.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cli-engine/formatters/json.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cli-engine/formatters/stylish.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cli-engine/hash.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/cli-engine/lint-result-cache.js` (safe): No malicious patterns detected; the code is a legitimate ESLint lint result caching utility with expected file I/O and no suspicious behaviors.
- `lib/config-api.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/config/config-loader.js` (safe): This is the legitimate ESLint config loader; dynamic imports and require cache manipulation are intended features for loading user-owned config files, with no signs of exfiltration, credential harvesting, obfuscation, or process spawning.
- `lib/config/config.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/config/default-config.js` (safe): No malicious patterns detected; the code is a standard ESLint default configuration file that only requires internal modules and defines frozen configuration objects.
- `lib/config/flat-config-array.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/config/flat-config-schema.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/eslint/eslint-helpers.js` (safe): This is a legitimate ESLint helper module with only benign uses of dynamic imports and environment variables; no malicious patterns detected.
- `lib/eslint/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/source-code.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/backward-token-comment-cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/backward-token-cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/cursors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/decorative-cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/filter-cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/forward-token-comment-cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/forward-token-cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/limit-cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/padded-token-cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/skip-cursor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/source-code/token-store/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/languages/js/validate-language-options.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/apply-disable-directives.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/code-path-analysis/code-path-analyzer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/code-path-analysis/code-path-segment.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/code-path-analysis/code-path-state.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/code-path-analysis/code-path.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/code-path-analysis/debug-helpers.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/code-path-analysis/fork-context.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/code-path-analysis/id-generator.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/esquery.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/file-context.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/file-report.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/interpolate.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/linter.js` (safe): This is the legitimate ESLint Linter implementation; no malicious patterns, external data exfiltration, obfuscated code, or suspicious process/network activity were detected.
- `lib/linter/rule-fixer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/source-code-fixer.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/source-code-traverser.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/source-code-visitor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/linter/timing.js` (safe): No malicious patterns detected
- `lib/linter/vfile.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/options.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rule-tester/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rule-tester/rule-tester.js` (safe): No malicious patterns detected; the code is a standard ESLint RuleTester utility that performs local rule validation without exfiltration, credential harvesting, dynamic code execution, or suspicious filesystem/network activity.
- `lib/rules/accessor-pairs.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/array-bracket-newline.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/array-bracket-spacing.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/array-callback-return.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/array-element-newline.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/arrow-body-style.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/arrow-parens.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/arrow-spacing.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/block-scoped-var.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/block-spacing.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/brace-style.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/callback-return.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/camelcase.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/capitalized-comments.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/class-methods-use-this.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/comma-dangle.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/comma-spacing.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/comma-style.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/complexity.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/computed-property-spacing.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/consistent-return.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/consistent-this.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/constructor-super.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/curly.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/default-case-last.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/default-case.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/default-param-last.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/dot-location.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/dot-notation.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/eol-last.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/eqeqeq.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/for-direction.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/func-call-spacing.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/func-name-matching.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/func-names.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/func-style.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/function-call-argument-newline.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/function-paren-newline.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/generator-star-spacing.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/getter-return.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/global-require.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/grouped-accessor-pairs.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/guard-for-in.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/handle-callback-err.js` (safe): No malicious patterns detected; this is a standard deprecated ESLint rule for enforcing callback error handling.
- `lib/rules/id-blacklist.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/id-denylist.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/id-length.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/id-match.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/implicit-arrow-linebreak.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/indent-legacy.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/indent.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/init-declarations.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/jsx-quotes.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/key-spacing.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/keyword-spacing.js` (safe): No malicious patterns detected; this is a legitimate ESLint stylistic rule for keyword spacing that only performs static code analysis and auto-fixing.
- `lib/rules/line-comment-position.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/linebreak-style.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/lines-around-comment.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/lines-around-directive.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/lines-between-class-members.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/logical-assignment-operators.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/max-classes-per-file.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/max-depth.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/max-len.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/max-lines-per-function.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/max-lines.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/max-nested-callbacks.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/max-params.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/max-statements-per-line.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/max-statements.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/multiline-comment-style.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/multiline-ternary.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/new-cap.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/new-parens.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/newline-after-var.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/newline-before-return.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/newline-per-chained-call.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-alert.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-array-constructor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-async-promise-executor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-await-in-loop.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-bitwise.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-buffer-constructor.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-caller.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-case-declarations.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-catch-shadow.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-class-assign.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-compare-neg-zero.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-cond-assign.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-confusing-arrow.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-console.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-const-assign.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-constant-binary-expression.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-constant-condition.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-constructor-return.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-continue.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-control-regex.js` (safe): This is a standard ESLint rule implementation that analyzes regex literals for control characters using the regexpp validator, with no malicious patterns, network calls, file system access, or dynamic code execution.
- `lib/rules/no-debugger.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-delete-var.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-div-regex.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-dupe-args.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-dupe-class-members.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-dupe-else-if.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-dupe-keys.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-duplicate-case.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-duplicate-imports.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-else-return.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-empty-character-class.js` (safe): No malicious patterns detected; the file is a legitimate ESLint rule implementation for detecting empty character classes in regular expressions.
- `lib/rules/no-empty-function.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-empty-pattern.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-empty-static-block.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-empty.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-eq-null.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-eval.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-ex-assign.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-extend-native.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-extra-bind.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-extra-boolean-cast.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-extra-label.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-extra-parens.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-extra-semi.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-fallthrough.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-floating-decimal.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-func-assign.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-global-assign.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-implicit-coercion.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-implicit-globals.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-implied-eval.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-import-assign.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-inline-comments.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-inner-declarations.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-invalid-regexp.js` (safe): This is a standard ESLint rule implementation for validating RegExp constructor arguments, with no malicious patterns, network activity, file system access, or dynamic code execution.
- `lib/rules/no-invalid-this.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-irregular-whitespace.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-iterator.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rules/no-label-var.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
