Togoder security

Go package security report

github.com/thrasher-corp/gct-ta Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v0.0.0-20200623072738-f2b55b7f9f41 Files reviewed 9 Size 30.7 KB Scanned

Summary

Togoder Security scanned the Go package github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41 on Oct 5, 2026. An AI review of 9 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
3
low

Findings 4

medium

Unvalidated network request construction

NPS-98469558E452

Exchange, currency pair, and period values are taken directly from CLI flags and concatenated into the CryptoWatch API URL without validation or sanitization. While this is a CLI tool, an attacker who can influence these inputs could cause requests to unexpected hosts or paths (e.g., path traversal in exchange/pair segments), potentially leading to SSRF-like behavior or unintended API access.

cmd/gct-ta/main.go:333
low

Hardcoded external API endpoint

NPS-C50F8F897DBB

All data retrieval is directed to a hardcoded third-party API (https://api.cryptowat.ch). This is expected functionality but means the tool relies on an external service that could change or be compromised, affecting data integrity.

cmd/gct-ta/main.go:18
low

Insufficient HTTP error status handling

NPS-5F1CA03CF1B0

The code does not check resp.StatusCode after the HTTP request. It proceeds to read and parse the body even for 4xx/5xx responses, which could lead to parsing unexpected content or masking errors from the remote service.

cmd/gct-ta/main.go:351
low

Missing response body size limit

NPS-E585F0F6A731

ioutil.ReadAll is used to read the entire HTTP response body without any size restriction. A malicious or compromised remote server could return an extremely large response, causing memory exhaustion (denial of service).

cmd/gct-ta/main.go:355

Files reviewed

FileVerdictWhat the reviewer saw
cmd/gct-ta/main.go medium The code is a legitimate CLI indicator tool with no malicious exfiltration, credential harvesting, code execution, or backdoor patterns, but it has minor robustness issues such as unvalidated URL inputs and unbounded response reading.
indicators/atr.go safe Cleared by Jev triage; no further analysis needed
indicators/bbands.go safe Cleared by Jev triage; no further analysis needed
indicators/correlation.go safe Cleared by Jev triage; no further analysis needed
indicators/indicators.go safe Cleared by Jev triage; no further analysis needed
indicators/ma.go safe Cleared by Jev triage; no further analysis needed
indicators/mfi.go safe Cleared by Jev triage; no further analysis needed
indicators/obv.go safe Cleared by Jev triage; no further analysis needed
indicators/rsi.go safe Cleared by Jev triage; no further analysis needed

Scanned versions of github.com/thrasher-corp/gct-ta

VersionVerdictFilesScanned
v0.0.0-20200623072738-f2b55b7f9f41 Needs review 9 Oct 5, 2026

Frequently asked questions

Is github.com/thrasher-corp/gct-ta safe to use?

No confirmed malware was found in github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/thrasher-corp/gct-ta contain malware?

No malware was identified in github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/thrasher-corp/gct-ta checked?

Togoder Security downloaded the published Go package and had an AI model read its 9 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/thrasher-corp/gct-ta together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41, cost nothing.

Related security reports