# github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:09:05.000Z
- Files reviewed: 9
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/go/github.com/thrasher-corp/gct-ta
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/thrasher-corp/gct-ta@v0.0.0-20200623072738-f2b55b7f9f41 on Oct 5, 2026. An AI review of 9 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unvalidated network request construction

Finding ID: `NPS-98469558E452`

File: `cmd/gct-ta/main.go:333`

Exchange, currency pair, and period values are taken directly from CLI flags and concatenated into the CryptoWatch API URL without validation or sanitization. While this is a CLI tool, an attacker who can influence these inputs could cause requests to unexpected hosts or paths (e.g., path traversal in exchange/pair segments), potentially leading to SSRF-like behavior or unintended API access.

### [low] Hardcoded external API endpoint

Finding ID: `NPS-C50F8F897DBB`

File: `cmd/gct-ta/main.go:18`

All data retrieval is directed to a hardcoded third-party API (https://api.cryptowat.ch). This is expected functionality but means the tool relies on an external service that could change or be compromised, affecting data integrity.

### [low] Insufficient HTTP error status handling

Finding ID: `NPS-5F1CA03CF1B0`

File: `cmd/gct-ta/main.go:351`

The code does not check resp.StatusCode after the HTTP request. It proceeds to read and parse the body even for 4xx/5xx responses, which could lead to parsing unexpected content or masking errors from the remote service.

### [low] Missing response body size limit

Finding ID: `NPS-E585F0F6A731`

File: `cmd/gct-ta/main.go:355`

ioutil.ReadAll is used to read the entire HTTP response body without any size restriction. A malicious or compromised remote server could return an extremely large response, causing memory exhaustion (denial of service).

## Files reviewed

- `cmd/gct-ta/main.go` (medium): The code is a legitimate CLI indicator tool with no malicious exfiltration, credential harvesting, code execution, or backdoor patterns, but it has minor robustness issues such as unvalidated URL inputs and unbounded response reading.
- `indicators/atr.go` (safe): Cleared by Jev triage; no further analysis needed
- `indicators/bbands.go` (safe): Cleared by Jev triage; no further analysis needed
- `indicators/correlation.go` (safe): Cleared by Jev triage; no further analysis needed
- `indicators/indicators.go` (safe): Cleared by Jev triage; no further analysis needed
- `indicators/ma.go` (safe): Cleared by Jev triage; no further analysis needed
- `indicators/mfi.go` (safe): Cleared by Jev triage; no further analysis needed
- `indicators/obv.go` (safe): Cleared by Jev triage; no further analysis needed
- `indicators/rsi.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
