# rc@1.2.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:39:53.000Z
- Files reviewed: 4
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/rc
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package rc@1.2.8 on Oct 4, 2026. An AI review of 4 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Potential undefined variable issue

Finding ID: `NPS-E8E36CF6929D`

File: `index.js:5`

The variable 'home' is assigned from process.env.HOME or process.env.USERPROFILE, but if neither is set, home becomes undefined. The subsequent check 'if (home)' guards against this, but it's a potential edge case.

### [low] Environment variable harvesting

Finding ID: `NPS-372ACB5643AD`

File: `index.js:7`

The code reads environment variables including process.env.HOME, process.env.USERPROFILE, and dynamically constructs and reads environment variables prefixed with the package name (cc.env(name + '_')). This is legitimate for a configuration loader (rc) but could theoretically leak sensitive env vars if misused.

### [low] Dynamic module loading with external input

Finding ID: `NPS-5B764319BC5B`

File: `index.js:12`

The code requires 'minimist' and 'deep-extend' modules and uses cc.parse (possibly a custom parser). It also processes configuration files and command-line arguments dynamically, which could be exploited if the parser has vulnerabilities.

### [low] File system access outside package scope

Finding ID: `NPS-5680BE855836`

File: `index.js:32`

The module reads configuration files from system and user directories including /etc/<name>/config, /etc/<name>rc, ~/.config/<name>/config, ~/.config/<name>, ~/.<name>/config, ~/.<name>rc, and current directory. While this is the intended behavior of an rc configuration loader, it accesses files outside the package scope.

## Files reviewed

- `index.js` (medium): The code appears to be a legitimate configuration loader (rc) that reads config files and environment variables, with no clear malicious patterns such as data exfiltration or code execution, but it does access sensitive file system locations and environment variables as part of its normal operation.
- `browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `cli.js` (safe): No malicious patterns detected; the CLI simply loads the local index module and prints its result as JSON.
- `lib/utils.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
