Togoder security

Go package security report

github.com/cpuguy83/go-md2man/v2@v2.0.7 security report

No malicious code found.

No issues Version v2.0.7 Files reviewed 4 Size 14.2 KB Scanned

Summary

Togoder Security scanned the Go package github.com/cpuguy83/go-md2man/v2@v2.0.7 on Oct 5, 2026. An AI review of 4 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
2
low

Findings 2

low

No input validation on file paths

NPS-1C3152ADB773

The program accepts arbitrary input and output file paths from command-line flags without validation. This could be used to overwrite arbitrary files if the program is run with elevated privileges, but it is standard CLI behavior.

md2man.go:25
low

Unsafe file permissions

NPS-217CD7EF68E6

The script uses os.Create which creates files with mode 0666 before umask. This is typically masked to 0644 or 0600 in usual environments, but without explicit permission setting, it could be insecure depending on umask.

md2man.go:40

Files reviewed

FileVerdictWhat the reviewer saw
md2man.go safe The code is a standard CLI tool for converting markdown to man pages, with no malicious patterns, but has minor security hygiene concerns around file permissions and path handling.
md2man/debug.go safe Cleared by Jev triage; no further analysis needed
md2man/md2man.go safe No malicious patterns detected
md2man/roff.go safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is github.com/cpuguy83/go-md2man/v2 safe to use?

Our AI source review of github.com/cpuguy83/go-md2man/v2@v2.0.7 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does github.com/cpuguy83/go-md2man/v2 contain malware?

No malware was identified in github.com/cpuguy83/go-md2man/v2@v2.0.7 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/cpuguy83/go-md2man/v2 checked?

Togoder Security downloaded the published Go package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/cpuguy83/go-md2man/v2 together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/cpuguy83/go-md2man/v2@v2.0.7, cost nothing.

Related security reports