# generator-function@2.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:31:55.000Z
- Files reviewed: 4
- Findings: 1 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/generator-function
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package generator-function@2.0.1 on Oct 4, 2026. An AI review of 4 source files produced 1 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution via Function constructor

Finding ID: `NPS-5A747D325370`

File: `index.js:4`

The code accesses the Function constructor through a generator function instance (function* () {}.constructor) and exports it. This is a common technique to obtain the Function constructor without triggering lint rules or static analysis checks, and can be used to dynamically execute arbitrary code (equivalent to new Function). While the code itself only caches and returns the constructor, exposing this pattern in a public package could be leveraged by downstream consumers or indicate an attempt to evade code review tooling.

### [low] Dynamic code execution

Finding ID: `NPS-2372E3BA2DD2`

File: `legacy.js:11`

Uses the Function constructor with a fixed string to detect the GeneratorFunction constructor. This is a dynamic code execution pattern and may be flagged by security tooling or blocked by strict CSP, though no external or user-controlled input is evaluated.

## Files reviewed

- `index.js` (medium): The file exports a cached reference to the Function constructor via an unusual generator-based access pattern, which is a code-execution primitive often used for obfuscation or lint evasion, though no active malicious behavior is present in this snippet.
- `legacy.js` (medium): The file uses Function constructor for a benign feature detection, presenting a low-risk dynamic code execution pattern without exfiltration, environment access, or other malicious behavior.
- `index.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `require.mjs` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
