# proto-list@1.2.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:49.000Z
- Files reviewed: 1
- Findings: 2 medium severity findings
- Report: https://security.togoder.click/npm/proto-list
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package proto-list@1.2.4 on Oct 6, 2026. An AI review of 1 source file produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Prototype pollution

Finding ID: `NPS-F6F42883905B`

File: `proto-list.js`

The ProtoList class manipulates object prototypes via Object.setPrototypeOf / __proto__, which can lead to prototype pollution. The `set` and `push` methods allow setting arbitrary keys on the prototype chain, potentially affecting all objects inheriting from the same prototype. This is a known security risk in JavaScript.

### [medium] Potential for prototype chain manipulation

Finding ID: `NPS-459C4BF56031`

File: `proto-list.js`

The `root` setter and methods like `push`, `unshift`, `pop`, `shift`, and `splice` dynamically alter the prototype of objects in the list. This could be abused if untrusted input controls the objects or keys, leading to unexpected behavior or privilege escalation in certain contexts.

## Files reviewed

- `proto-list.js` (medium): The code is a utility for managing a prototype-based linked list and does not contain obvious malicious patterns, but it exposes prototype pollution risks that could be exploited if used with untrusted data.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
