# get-symbol-description@1.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:16:42.000Z
- Files reviewed: 2
- Findings: 1 medium severity finding
- Report: https://security.togoder.click/npm/get-symbol-description
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package get-symbol-description@1.1.0 on Oct 6, 2026. An AI review of 2 source files produced 1 medium severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-2F484DAB986F`

File: `getInferredName.js:8`

The code uses the Function constructor to dynamically create a function that reads the name property of an object's method. While this is a known technique for feature detection of inferred function names, using new Function/eval-like constructs can be abused in some contexts and is generally flagged as a potential security concern. Here it appears benign for its intended purpose.

## Files reviewed

- `getInferredName.js` (medium): Uses the Function constructor for feature detection of function name inference, which is a dynamic code execution pattern but appears benign in this context.
- `index.js` (safe): No malicious patterns detected; the code is a legitimate polyfill for Symbol.prototype.description with no network, filesystem, or process activity.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
