Summary
Togoder Security scanned the Go package github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc on Oct 5, 2026. An AI review of 9 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Unsafe package usage / Reflect internals manipulation
NPS-8F751DACF39B
The code uses the unsafe package to directly manipulate unexported fields of reflect.Value (specifically the internal 'flag' field) to bypass Go's type safety and read unexported struct fields. While this is a legitimate technique used by the spew library for pretty-printing, it circumvents Go's memory safety guarantees and relies on internal implementation details that could change between Go versions.
Build constraint to enable unsafe code
NPS-E690DB8025FC
The build constraints (!js,!appengine,!safe,!disableunsafe,go1.4) are designed to ensure this unsafe reflection-bypassing code is compiled in by default. The 'safe' tag is an opt-out mechanism, meaning most builds will include the unsafe code automatically without explicit developer consent, which is a questionable default for a library that bypasses type safety.
Init-time reflection and panic behavior
NPS-FECA4AE463C6
The init() function performs runtime introspection of the reflect package's internal layout at import time. It will panic if the reflect.Value flag semantics don't match expected values. This runs automatically on package import and could cause denial of service in applications using this package if Go's reflect internals change, though this is defensive rather than malicious.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| spew/bypass.go | medium | This is a legitimate library file (part of spew) that intentionally uses unsafe reflection internals to access unexported fields for pretty-printing, but it bypasses Go's type safety guarantees and should be reviewed for supply-chain risk if the maintainer or version provenance is untrusted. |
| spew/bypasssafe.go | safe | Cleared by Jev triage; no further analysis needed |
| spew/common.go | safe | No malicious patterns detected |
| spew/config.go | safe | Cleared by Jev triage; no further analysis needed |
| spew/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| spew/dump.go | safe | No malicious patterns detected; the code is a legitimate reflection-based pretty-printer with no network, filesystem, process, or dynamic-execution capabilities. |
| spew/format.go | safe | Cleared by Jev triage; no further analysis needed |
| spew/spew.go | safe | Cleared by Jev triage; no further analysis needed |
| spew/testdata/dumpcgo.go | safe | No malicious patterns detected in this cgo test file that only contains static C char pointer definitions and test-only accessor functions. |
Frequently asked questions
Is github.com/davecgh/go-spew safe to use?
No confirmed malware was found in github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/davecgh/go-spew contain malware?
No malware was identified in github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/davecgh/go-spew checked?
Togoder Security downloaded the published Go package and had an AI model read its 9 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/davecgh/go-spew together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/davecgh/go-spew@v1.1.2-0.20180830191138-d8f796af33cc, cost nothing.