# slow-redact@0.3.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T21:17:57.000Z
- Files reviewed: 5
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/slow-redact
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package slow-redact@0.3.2 on Oct 4, 2026. An AI review of 5 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Install/build-time execution surface

Finding ID: `NPS-BA28AF6ECEC4`

File: `scripts/sync-version.mjs:9`

This is a lifecycle/build helper script. When wired into npm scripts (e.g., prepublish, preinstall, version), it executes automatically and mutates package.json based on attacker-influenced argv input without validating the version string against a semver regex or allowlist. Unsanitized input is written directly into package.json, which can enable supply-chain version-spoofing or injection if the file is later published.

### [medium] File system manipulation

Finding ID: `NPS-1151842655DE`

File: `scripts/sync-version.mjs:16`

The script reads and writes package.json. While reading is expected, the write operation uses a hardcoded relative path './package.json' instead of the resolved absolute path 'packageJsonPath' used for reading. This causes the write to target a potentially different file depending on the current working directory, which is inconsistent and could be exploited if the script is invoked from an unexpected directory (e.g., overwriting an unintended package.json outside the intended scope).

### [low] Test credentials

Finding ID: `NPS-E37F375744C9`

File: `benchmarks/basic.js:8`

Hard-coded test secrets (passwords, cookies, API keys) are present in benchmark fixtures. These are dummy values for performance testing and are not harvested or exfiltrated.

## Files reviewed

- `scripts/sync-version.mjs` (medium): No overtly malicious behavior (no network calls, credential access, obfuscation, or process spawning), but the script performs unvalidated filesystem writes to a relative path based on user-supplied input, posing a supply-chain tampering risk.
- `benchmarks/basic.js` (safe): The file is a benchmark script for redaction libraries and contains no malicious behavior such as data exfiltration, credential harvesting, obfuscation, or process execution.
- `eslint.config.js` (safe): No malicious patterns detected
- `index.js` (safe): No malicious patterns detected
- `index.test-d.ts` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
