# stream-chain@2.2.5 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:40:55.000Z
- Files reviewed: 14
- Findings: no findings
- Report: https://security.togoder.click/npm/stream-chain
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package stream-chain@2.2.5 on Oct 4, 2026. An AI review of 14 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `defs.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): No malicious patterns detected; the code implements a stream utility library with no network, filesystem, process, or dynamic code execution behavior.
- `utils/FromIterable.js` (safe): No malicious patterns detected
- `utils/Reduce.js` (safe): No malicious patterns detected; the code is a simple stream reducer implementation with no network, filesystem, process execution, or obfuscation concerns.
- `utils/asFun.js` (safe): No malicious patterns detected; the code is a functional utility for composing async functions with no network, filesystem, or dynamic execution behavior.
- `utils/asGen.js` (safe): No malicious patterns detected; the code is a utility for composing async generator functions without any network, filesystem, or command execution activity.
- `utils/comp.js` (safe): The code implements a stream transform composition utility using standard modules and no malicious patterns were detected.
- `utils/fold.js` (safe): No malicious patterns detected; the code is a standard stream Transform implementation for folding/reducing data.
- `utils/gen.js` (safe): No malicious patterns detected; the code is a stream transform utility with no network, filesystem, process, or obfuscated behavior.
- `utils/scan.js` (safe): No malicious patterns detected; the code is a benign stream transform utility implementing a scan/reduce operation.
- `utils/skip.js` (safe): Cleared by Jev triage; no further analysis needed
- `utils/skipWhile.js` (safe): No malicious patterns detected; the code implements a standard SkipWhile transform stream with no network, filesystem, process, or dynamic code execution concerns.
- `utils/take.js` (safe): Cleared by Jev triage; no further analysis needed
- `utils/takeWhile.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
