# handlebars@4.7.9 — Threat Briefing Low risk — threat briefing for npm package handlebars@4.7.9. Capabilities, risk paths, and what to check. - **Ecosystem:** npm - **Latest version:** 4.7.8 - **License:** MIT ## Risk - **Level:** low - **Summary:** No risky changes detected ## Capability Summary | Capability | Level | |---|---| | install scripts | none | | network access | none | | filesystem | both | | shell execution | none | ## Capabilities ### Execution - CLI command installation [common] - Dynamic code execution (eval) [unusual] ### Other - Long encoded payload [common] ### Filesystem - Filesystem read [common] - Filesystem write [common] ## Key Signals - **** ## Trust Signals ### Code Safety - No access to sensitive paths - No network activity during install ## Maintainer