Togoder security

Go package security report

github.com/klauspost/cpuid/v2 Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v2.2.9 Files reviewed 11 Size 84.0 KB Scanned

Summary

Togoder Security scanned the Go package github.com/klauspost/cpuid/v2@v2.2.9 on Oct 5, 2026. An AI review of 11 source files produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
2
low

Findings 4

medium

import-time execution

NPS-6C3311CD968E

The package runs init() at import time which calls initCPU() and Detect(). Detect() parses command-line flags (cpu.disable, cpu.features, cpu.arm) and may call os.Exit(1) if -cpu.features is set. This is a behavior that modifies process behavior and can terminate the host program unexpectedly based solely on ambient flag values, which is unusual for a library.

cpuid.go:293
medium

process termination from library code

NPS-CA02678BEF26

The Detect() function calls os.Exit(1) when the -cpu.features flag is enabled. Library code should not terminate the calling process; this can be abused or cause unexpected denial of service when flags are supplied by a parent process.

cpuid.go:316
low

global flag registration side effect

NPS-C296ED3693AA

Flags() registers global command-line flags (cpu.disable, cpu.features, cpu.arm) which, if called before flag.Parse, influences parsing of the host application's command line. This is a side effect not typical for a CPU detection library and could interfere with the host program.

cpuid.go:352
low

use of go:linkname

NPS-4F4592837213

This file uses //go:linkname to access the unexported symbol internal/cpu.HWCap from the Go standard library. While not inherently malicious, go:linkname is a powerful unsafe mechanism that bypasses Go's type safety and module boundaries. It relies on undocumented internal implementation details, may break across Go versions, and can be abused to access or alter internal runtime/stdlib state. It is gated behind a build tag (!nounsafe), which is a reasonable mitigation. No data exfiltration, credential harvesting, process spawning, or dynamic code execution is present.

os_unsafe_linux_arm64.go:9

Files reviewed

FileVerdictWhat the reviewer saw
cpuid.go medium The cpuid library contains import-time CPU detection and command-line flag/exit side effects, but no data exfiltration, credential harvesting, obfuscation, network activity, or process spawning was observed.
os_unsafe_linux_arm64.go medium The file is not malicious but uses the unsafe go:linkname directive to access an internal standard library symbol, which warrants caution due to its fragility and potential for abuse.
cmd/cpuid/main.go safe No malicious patterns detected
detect_arm64.go safe No malicious patterns detected
detect_ref.go safe No malicious patterns detected; the file contains only stub implementations for CPU feature detection on unsupported architectures.
detect_x86.go safe No malicious patterns detected; the file contains only CPU feature detection declarations and initialization for x86 architectures.
featureid_string.go safe No malicious patterns detected
os_darwin_arm64.go safe No malicious patterns detected; the code only reads macOS sysctl values to populate CPU feature information.
os_linux_arm64.go safe No malicious patterns detected
os_other_arm64.go safe No malicious patterns detected; the file only reads CPU core counts via runtime.NumCPU for ARM64 non-Linux/non-Darwin platforms.
os_safe_linux_arm64.go safe Cleared by Jev triage; no further analysis needed

Scanned versions of github.com/klauspost/cpuid/v2

VersionVerdictFilesScanned
v2.2.9 Needs review 11 Oct 5, 2026

Frequently asked questions

Is github.com/klauspost/cpuid/v2 safe to use?

No confirmed malware was found in github.com/klauspost/cpuid/v2@v2.2.9, but the review flagged 2 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/klauspost/cpuid/v2 contain malware?

No malware was identified in github.com/klauspost/cpuid/v2@v2.2.9 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/klauspost/cpuid/v2 checked?

Togoder Security downloaded the published Go package and had an AI model read its 11 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/klauspost/cpuid/v2 together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/klauspost/cpuid/v2@v2.2.9, cost nothing.

Related security reports