# node-addon-api@7.1.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:22:52.000Z
- Files reviewed: 5
- Findings: 4 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/node-addon-api@7.1.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package node-addon-api@7.1.1 on Oct 6, 2026. An AI review of 5 source files produced 4 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unvalidated User-Controlled Target Directory

Finding ID: `NPS-66FE267154AF`

File: `tools/conversion.js:8`

The target directory is taken directly from process.argv without any path validation, canonicalization, or confinement. An attacker who can influence the arguments (e.g., via a wrapper script or CI configuration) could direct the tool to rewrite arbitrary files on the filesystem, achieving data destruction or tampering with build configurations.

### [medium] Shell Command Injection via binding.gyp Rewrite

Finding ID: `NPS-E59B405D0838`

File: `tools/conversion.js:26`

The script injects '<!(node -p "require('node-addon-api').include_dir")' expressions into binding.gyp files. These gyp directives execute shell commands at build time. While intended for legitimate include_dir resolution, this introduces build-time command execution into any target project that processes the rewritten binding.gyp, which is a potential supply-chain risk if the target project is later built in an untrusted context.

### [medium] Unbounded Recursive File Rewrite

Finding ID: `NPS-385B49F0E3D5`

File: `tools/conversion.js:297`

convertFile uses fs.writeFile without validation of the target path against the package scope or a safe root. Combined with listFiles skipping only 'node_modules', the tool will rewrite every matching source/config file in the given directory tree, including files in user projects, home directories, or system paths if the user passes such a path. This is a destructive file-system operation outside the package's own scope.

### [medium] Filesystem Modification

Finding ID: `NPS-79186E9905D9`

File: `tools/conversion.js:305`

The script recursively scans and modifies files (package.json, binding.gyp, .h, .cc, .cpp) in a user-specified directory. This is expected behavior for a migration tool (nan to node-addon-api), but it performs bulk in-place rewrites outside the package's own scope if pointed at arbitrary directories. A malicious or careless invocation could corrupt or alter unrelated projects.

### [low] Process spawning

Finding ID: `NPS-7619CE794D01`

File: `tools/check-napi.js:12`

The script uses child_process.spawn() to execute external commands 'nm' (on Unix) and 'dumpbin' (on Windows) against discovered .node files. While this appears to be for legitimate N-API symbol inspection, spawning external processes is a notable security-relevant behavior that could be abused if the script's logic were altered or if the target files were attacker-controlled.

### [low] File system traversal

Finding ID: `NPS-8B6E2CAF218E`

File: `tools/check-napi.js:76`

The recurse() function recursively walks the file system starting from a directory supplied via process.argv (defaults to current directory). It reads directory contents and stats files outside the package's own scope. This is expected for a developer tool but represents file system access beyond the package directory.

### [low] Top-level execution on import

Finding ID: `NPS-2A671E6FAA62`

File: `tools/check-napi.js:110`

The script executes recurse() at the top level (line 110) based on process.argv. If this file were required as a module rather than run as a CLI script, it would still perform file system traversal and process spawning. However, the code is clearly intended as a CLI tool (tools/check-napi.js) and this behavior is expected.

### [low] Environment Variable Use

Finding ID: `NPS-4C06A2D1A517`

File: `tools/eslint-format.js:4`

Reads process.env.FORMAT_START to control the git diff base reference. This is a benign configuration option but could be manipulated by an attacker with control over the environment to alter which files are checked.

### [low] Process Spawning

Finding ID: `NPS-9E218AE14A7F`

File: `tools/eslint-format.js:23`

Uses child_process.spawnSync to execute git and eslint binaries. While the paths are fixed and arguments are constructed from git output, this is a legitimate pattern for a linting tool but warrants attention as a process-spawning operation.

### [low] Command Execution via External Binary

Finding ID: `NPS-A29989F91C81`

File: `tools/eslint-format.js:51`

Spawns the local ESLint binary from node_modules with file paths derived from git diff output. The file paths are passed as separate array arguments (not through a shell), so command injection risk is mitigated, but the tool executes an external binary present in the package's node_modules.

## Files reviewed

- `tools/check-napi.js` (medium): The script is a legitimate developer utility for detecting N-API modules via nm/dumpbin; it spawns external processes and traverses the file system as intended, with no evidence of exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `tools/conversion.js` (medium): The script is a legitimate nan-to-node-addon-api migration tool but performs unrestricted, unvalidated in-place recursive file rewrites and injects build-time shell-executing gyp directives, posing a moderate supply-chain/destructive-operation risk.
- `tools/eslint-format.js` (medium): This is a legitimate ESLint formatting helper script that spawns git and eslint processes; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoor installation were detected, though it does use child_process and environment variables in normal ways.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `tools/clang-format.js` (safe): No malicious patterns detected

## Version ranges

None of the 2 scanned versions of node-addon-api are flagged high or critical. The latest scanned version, 8.9.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.3.1 – 8.9.0 (`>=8.3.1 <=8.9.0`): not scanned
- 7.1.1 (`7.1.1`): medium (Filesystem Modification +3 more)
- 3.2.1 – 7.1.0 (`>=3.2.1 <=7.1.0`): not scanned
- 2.0.2 (`2.0.2`): medium (File system manipulation outside package scope +2 more)

## Scanned versions

- [7.1.1](https://security.togoder.click/npm/node-addon-api@7.1.1): medium, 2026-10-06T14:22:52.000Z
- [2.0.2](https://security.togoder.click/npm/node-addon-api@2.0.2): medium, 2026-10-04T16:35:41.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
