# xmlhttprequest@1.8.0 — Threat Briefing Low risk — threat briefing for npm package xmlhttprequest@1.8.0. Capabilities, risk paths, and what to check. - **Ecosystem:** npm - **Latest version:** 1.8.0 - **License:** MIT ## Risk - **Level:** low - **Summary:** No risky changes detected ## Capability Summary | Capability | Level | |---|---| | install scripts | none | | network access | client | | filesystem | both | | shell execution | exec | ## Capabilities ### Filesystem - Filesystem read [common] - Filesystem write [common] ### Network - Network client [common] ### Execution - Shell execution [unusual] ## Trust Signals ### Code Safety - No obfuscated or encoded payloads - No dynamic code execution - No access to sensitive paths - No network activity during install ## Maintainer