# read-cmd-shim@6.0.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:32.000Z
- Files reviewed: 1
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/read-cmd-shim
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package read-cmd-shim@6.0.0 on Oct 6, 2026. An AI review of 1 source file produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] regular expression complexity

Finding ID: `NPS-A46DEC8E660D`

File: `lib/index.js`

The regex patterns used in extractPathFromPowershell, extractPathFromCmd, and extractPathFromCygwin are relatively simple and not prone to catastrophic backtracking, but they dynamically parse text files. If an attacker controls the shim file content, they could craft malicious input, though the impact is limited to incorrect path extraction, not code execution. This is a low-severity concern.

### [low] file system manipulation

Finding ID: `NPS-8FEC4FC6FACC`

File: `lib/index.js`

The module reads files from the filesystem (readFileSync and readFile) based on the provided path. It does not restrict paths to a specific directory, so it could be used to read arbitrary files if the calling code passes attacker-controlled paths. However, this is a typical utility behavior for a cmd-shim parser and does not itself indicate malicious intent.

### [low] error handling information exposure

Finding ID: `NPS-22D9841D781C`

File: `lib/index.js`

Error objects include file paths and error codes, which could leak sensitive path information if errors are logged or displayed to untrusted users. This is a minor information disclosure concern.

## Files reviewed

- `lib/index.js` (medium): The code is a benign utility for reading and parsing cmd-shim files, with no malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
