# github.com/cpuguy83/go-md2man/v2@v2.0.7 security report (Go)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-05T19:10:30.000Z
- Files reviewed: 4
- Findings: 2 low severity findings
- Report: https://security.togoder.click/go/github.com/cpuguy83/go-md2man/v2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/cpuguy83/go-md2man/v2@v2.0.7 on Oct 5, 2026. An AI review of 4 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] No input validation on file paths

Finding ID: `NPS-1C3152ADB773`

File: `md2man.go:25`

The program accepts arbitrary input and output file paths from command-line flags without validation. This could be used to overwrite arbitrary files if the program is run with elevated privileges, but it is standard CLI behavior.

### [low] Unsafe file permissions

Finding ID: `NPS-217CD7EF68E6`

File: `md2man.go:40`

The script uses os.Create which creates files with mode 0666 before umask. This is typically masked to 0644 or 0600 in usual environments, but without explicit permission setting, it could be insecure depending on umask.

## Files reviewed

- `md2man.go` (safe): The code is a standard CLI tool for converting markdown to man pages, with no malicious patterns, but has minor security hygiene concerns around file permissions and path handling.
- `md2man/debug.go` (safe): Cleared by Jev triage; no further analysis needed
- `md2man/md2man.go` (safe): No malicious patterns detected
- `md2man/roff.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
