# get-intrinsic@1.3.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T14:37:31.000Z
- Files reviewed: 1
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/get-intrinsic
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package get-intrinsic@1.3.0 on Oct 4, 2026. An AI review of 1 source file produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-C204B37A32B4`

File: `index.js:28`

The getEvalledConstructor function uses the Function constructor to dynamically evaluate strings like 'async function () {}' to obtain constructors for intrinsics that are not directly accessible. While the inputs are static, hardcoded strings, this pattern is a form of eval and can be risky if input ever becomes tainted.

### [low] Access to Function constructor

Finding ID: `NPS-6679AC387A3C`

File: `index.js:22`

var $Function = Function; stores a reference to the global Function constructor, which can be used to create functions from strings. Again, only used with static strings in this file.

### [low] Use of eval

Finding ID: `NPS-F236948C1DB2`

File: `index.js:96`

The INTRINSICS object includes '%eval%': eval, exposing the global eval function. This is part of the intrinsic collection and not directly invoked here, but its inclusion could be abused by consumers of this module.

## Files reviewed

- `index.js` (medium): This appears to be a legitimate polyfill/library for accessing JavaScript intrinsics (likely es-abstract's GetIntrinsic), using dynamic Function construction with hardcoded strings; no malicious data exfiltration, credential harvesting, network activity, or backdoor patterns were detected, but the dynamic code execution patterns warrant caution.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
