# obug@2.2.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:23:40.000Z
- Files reviewed: 4
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/obug
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package obug@2.2.1 on Oct 6, 2026. An AI review of 4 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Environment Variable Access

Finding ID: `NPS-E951E08483EB`

File: `dist/ansi.js:3`

The code reads process.env.DEBUG and filters keys matching /^debug_/i to build inspect options. This is standard behavior for the debug package to allow configuration via environment variables. No sensitive credentials (npmrc, pypirc, ssh keys, etc.) are read or exfiltrated.

### [low] Terminal Detection

Finding ID: `NPS-E496904A69B7`

File: `dist/ansi.js:3`

Uses node:tty isatty and process.stderr.getColorDepth to determine color support. This is benign terminal capability probing, not a security concern.

### [low] Output Formatting

Finding ID: `NPS-B2A8DB8ACADE`

File: `dist/ansi.js:110`

Writes formatted log messages to process.stderr. No file system writes, network requests, or process spawning occur.

## Files reviewed

- `dist/ansi.js` (safe): The file is a standard ANSI/debug logging module with benign environment reading and terminal detection; no malicious patterns found.
- `dist/browser.js` (safe): No malicious patterns detected; this is a standard browser build of the debug library with expected color formatting, namespace persistence, and console logging behavior.
- `dist/core.js` (safe): No malicious patterns detected
- `dist/plain.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
