# tinyglobby@0.2.17 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-06T14:23:36.000Z
- Files reviewed: 2
- Findings: 6 low severity findings
- Report: https://security.togoder.click/npm/tinyglobby
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package tinyglobby@0.2.17 on Oct 6, 2026. An AI review of 2 source files produced 6 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] filesystem traversal

Finding ID: `NPS-AC990BC28E52`

File: `dist/index.mjs`

The package uses fdir to crawl the filesystem based on glob patterns. While this is expected behavior for a globbing library, it does not appear to escape the provided working directory or access sensitive files beyond user-specified patterns.

### [low] symbolic link following

Finding ID: `NPS-9B288420F744`

File: `dist/index.mjs`

The default option followSymbolicLinks is true, which could potentially follow symlinks outside the intended directory. However, this is a documented feature of the library and not inherently malicious.

### [low] command execution

Finding ID: `NPS-D9F37ED6C712`

File: `dist/index.mjs`

No spawning of processes or shell commands was detected.

### [low] data exfiltration

Finding ID: `NPS-A560CE530CF2`

File: `dist/index.mjs`

No network requests or data exfiltration patterns were found.

### [low] environment variable harvesting

Finding ID: `NPS-95A362DCFD5C`

File: `dist/index.mjs`

Only TINYGLOBBY_DEBUG is read for debug logging; no sensitive environment variables are collected or transmitted.

### [low] obfuscation

Finding ID: `NPS-900E60020A20`

File: `dist/index.mjs`

No obfuscated code or dynamic code execution (eval, Function, etc.) was observed.

## Files reviewed

- `dist/index.cjs` (safe): No malicious patterns detected; this is the legitimate tinyglobby file-globbing library with standard Node.js fs/path usage and no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `dist/index.mjs` (safe): The code appears to be a legitimate globbing library with no malicious patterns detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
