# promzard@3.0.1 security report (npm)

- Verdict: **Critical risk** (risk level: critical)
- Scanned: 2026-10-06T14:23:32.000Z
- Files reviewed: 1
- Findings: 2 critical, 2 high, 1 medium severity findings
- Report: https://security.togoder.click/npm/promzard
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package promzard@3.0.1 on Oct 6, 2026. An AI review of 1 source file produced 2 critical, 2 high, 1 medium severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

## Findings

### [critical] Arbitrary code execution via file loading

Finding ID: `NPS-985DCAFF42B5`

File: `lib/index.js:57`

The PromZard class reads a file (or uses an in-memory buffer via fromBuffer) and executes its contents. The file path is user-controlled (constructor parameter). This allows loading and executing any JavaScript file on the system, leading to code execution.

### [critical] Dynamic code execution

Finding ID: `NPS-7A6E46D3D7AB`

File: `lib/index.js:62`

The code uses vm.runInThisContext() to execute the contents of a file or buffer as JavaScript within the current context. This is effectively eval() and allows arbitrary code execution from the loaded file/buffer. If an attacker can control the file path or buffer, they can execute arbitrary code with the privileges of the process.

### [high] Module loading with computed input

Finding ID: `NPS-B2301F28C891`

File: `lib/index.js:50`

The code creates a new Module and uses Module._nodeModulePaths and Module._resolveFilename with a path derived from the input file. This can be abused to load arbitrary modules from attacker-controlled locations, potentially leading to further code execution or module hijacking.

### [high] Exposed require function

Finding ID: `NPS-194F268004EB`

File: `lib/index.js:58`

The context object passed to the executed code includes a require function bound to the module, allowing the executed script to load any module available in the Node.js environment. This could be used to access sensitive modules like child_process, fs, etc., enabling further malicious actions.

### [medium] Prompt injection and callback execution

Finding ID: `NPS-F8EAA728A0CE`

File: `lib/index.js:106`

The #walk method iterates over object properties and executes functions with callbacks, and processes prompts. An attacker-controlled script could define functions that are automatically invoked, leading to arbitrary code execution during the walk process.

## Files reviewed

- `lib/index.js` (critical): The code executes arbitrary JavaScript from files or buffers using vm.runInThisContext, and provides a require function to the executed code, creating a critical code execution vulnerability.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
