# unicorn-magic@0.3.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:45.000Z
- Files reviewed: 2
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/unicorn-magic@0.3.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package unicorn-magic@0.3.0 on Oct 6, 2026. An AI review of 2 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Process execution utilities exported

Finding ID: `NPS-66E004373CB3`

File: `node.js:33`

The module exports wrappers around child_process.execFile and execFileSync with a raised maxBuffer. While these are standard APIs and no user-controlled input is used to construct commands in this file, exporting them allows arbitrary subprocess execution by consumers. This is not inherently malicious but is a capability worth noting in a security review, especially since the exported functions accept an 'options' object that is spread after the defaults, permitting callers to override security-relevant options like stdio, shell, uid/gid, env, etc.

### [low] Re-export of external module

Finding ID: `NPS-9A120F1488EA`

File: `node.js:52`

The file ends with 'export * from ./default.js', which re-exports all named exports from an unexamined local module. This could introduce additional attack surface if default.js contains malicious or unexpected behavior, but it cannot be assessed from the provided snippet.

## Files reviewed

- `node.js` (medium): The file contains no direct malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoors; it primarily provides path and child_process utility wrappers, though exporting subprocess execution helpers warrants caution.
- `default.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 3 scanned versions of unicorn-magic are flagged high or critical. The latest scanned version, 0.4.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 0.3.0 – 0.4.0 (`>=0.3.0 <=0.4.0`): medium
- 0.1.0 (`0.1.0`): clean

## Scanned versions

- [0.4.0](https://security.togoder.click/npm/unicorn-magic@0.4.0): medium, 2026-10-06T14:23:58.000Z
- [0.3.0](https://security.togoder.click/npm/unicorn-magic@0.3.0): medium, 2026-10-06T14:24:45.000Z
- [0.1.0](https://security.togoder.click/npm/unicorn-magic@0.1.0): safe, 2026-10-06T14:12:14.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
