Summary
Togoder Security scanned the Go package github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e on Oct 5, 2026. An AI review of 66 source files produced 5 medium, 12 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 17
Dynamic execution of external binaries
NPS-3ABD5F4C7B93
The execute function calls external binaries with arguments ('assemble', 'templates', 'imports') and passes JSON input via stdin. While this is the intended functionality of the driver, it relies on trust in the external binary. Malicious or compromised binaries could perform arbitrary actions, including data exfiltration, since they receive configuration data and run with the same privileges as the calling process.
Spawning processes or shell commands
NPS-213CB3D9C13B
The code uses os/exec to spawn external binaries based on the binaryDriver string. The executable path comes from the driver configuration and is passed directly to exec.Command without validation or sanitization. If an attacker can control the driver name (e.g., through configuration), they could execute arbitrary binaries on the system. This is a potential command execution vector.
Potential connection string injection / improper escaping
NPS-F9CE45EE6D39
PSQLBuildQueryString constructs a PostgreSQL connection string by directly interpolating user, password, dbname, host, and sslmode values with fmt.Sprintf without proper escaping. If any of these values contain spaces or special characters (e.g. a password with a space, or a host value containing ' sslmode=disable'), it could allow an attacker who controls config values to inject additional connection parameters, potentially weakening TLS (e.g. sslmode=disable) or redirecting connections. This is a classic connection-string injection pattern.
Process spawning
NPS-421844485C0B
preRun() uses exec.LookPath and later boilingcore registers the driver binary path; the driver is executed as an external process. While expected for this tool, the driver name/path is derived from user input and may be manipulated (e.g. path traversal via os.PathSeparator check) to execute an arbitrary binary.
Environment variable harvesting
NPS-304124D6AC14
allKeys() iterates over os.Environ() and collects all environment variables matching a prefix derived from user-supplied driver name, which could inadvertently capture sensitive environment variables (e.g. API keys, credentials) if they share the prefix. This data is then placed into DriverConfig and potentially passed to the driver binary.
Potential information disclosure via error handling
NPS-DB2AB2829C69
Error messages include the executable path and may leak details about the environment or configuration. While not directly malicious, verbose error messages could aid attackers in reconnaissance.
Untrusted input handling / missing bounds check
NPS-7006B259C9E6
os.Args[1] is accessed directly without verifying len(os.Args) > 1, which would cause a panic if the binary is invoked with no arguments. More importantly, the 'method' value is used to select driver behavior; if the driver implementation is supplied by a third party and the dispatcher is generic, unexpected methods are silently ignored (output remains nil), which could mask errors.
Potential information disclosure via verbose error output
NPS-C5CC27A04F91
When JSON parsing fails, the error handler prints the entire raw input buffer (b) to stderr. If the config contains secrets (tokens, credentials, environment-specific values), they could be leaked into logs or CI output. This is a minor concern for a driver helper but worth noting.
init() function registration
NPS-0E8499644FCA
The init() function registers a mock driver with the sqlboiler driver registry. This is a standard Go pattern for plugin registration in test/mock packages and does not perform any suspicious activity such as network access, file system manipulation, or code execution.
Panic recovery using unsafe type assertion
NPS-64A5A0FE2DA8
The deferred recover in Assemble does err = r.(error), which will itself panic if the recovered value is not an error (e.g. a string panic). This is not directly malicious, but it can crash the generator in unexpected ways and is a robustness concern rather than a security exploit.
Weak default TLS policy
NPS-3068265D1F0E
The default sslmode is set to 'require' which encrypts traffic but does not verify the server certificate (no hostname/cert verification). An attacker in a MITM position could impersonate the database server. Prefer 'verify-full' or 'verify-ca' for stronger guarantees.
Unbounded stderr output of database-derived identifiers
NPS-8FA2EBAE46F8
In TranslateColumnType, fmt.Fprintf(os.Stderr, "warning: incompatible data type detected: %s\n", c.UDTName) writes a database-controlled UDT name to stderr. While not a direct code execution vector, writing unsanitized database metadata to a terminal could enable terminal escape sequence injection if output is later reviewed in a vulnerable terminal. Typically low impact.
File system manipulation
NPS-5DAE8646DE92
The --wipe flag causes deletion of the output folder (rm -rf) before generation. If the output path is misconfigured or influenced by environment/config, it could delete unintended directories.
Dynamic code execution via templates
NPS-91AE7DF9739D
TemplateDirs and Replacements flags allow specifying external template directories and replacement files, which are processed at generation time. Malicious templates could execute arbitrary code within the generation context, though this is an intended feature.
Input validation using regex
NPS-FEC5C111309D
Uses rgxIdentifier and rgxInClause to validate and quote identifiers, reducing SQL injection risk.
SQL string concatenation
NPS-3B6830BCB3F1
Multiple places build SQL via string concatenation and fmt.Fprintf; however, identifiers are quoted and values use placeholders, mitigating injection.
Panic on invalid SQL structure
NPS-71934E381295
Calls panic in convertInQuestionMarks, convertQuestionMarks, whereClause, and buildSelectQuery (unsupported join kind). This is a reliability concern, not a security vulnerability.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| drivers/binary_driver.go | medium | The code spawns external binaries based on unvalidated input from driver configuration, which could lead to arbitrary command execution if the driver name is attacker-controlled; this is a medium-severity concern in a trusted driver context but warrants attention. |
| drivers/driver_main.go | medium | The file is a generic CLI dispatcher for driver plugins; it contains no exfiltration, credential harvesting, code execution, or network activity, but does leak raw stdin on JSON parse errors and lacks argument validation. |
| drivers/sqlboiler-psql/driver/psql.go | medium | No malicious code found; the driver is a legitimate sqlboiler PostgreSQL generator, but it builds connection strings via unsanitized string interpolation and defaults to a non-verifying SSL mode, which are minor security hygiene concerns rather than signs of malicious intent. |
| main.go | medium | The code is a legitimate CLI tool but contains patterns that could be abused if inputs are malicious, including environment variable collection, external binary execution, template-based code generation, and destructive file operations. |
| boil/columns.go | safe | Cleared by Jev triage; no further analysis needed |
| boil/db.go | safe | Cleared by Jev triage; no further analysis needed |
| boil/errors.go | safe | Cleared by Jev triage; no further analysis needed |
| boil/global.go | safe | No malicious patterns detected |
| boil/hooks.go | safe | Cleared by Jev triage; no further analysis needed |
| boilingcore/aliases.go | safe | Cleared by Jev triage; no further analysis needed |
| boilingcore/boilingcore.go | safe | No malicious patterns detected; the code is a legitimate SQLBoiler code generation library with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| boilingcore/config.go | safe | Cleared by Jev triage; no further analysis needed |
| boilingcore/output.go | safe | No malicious patterns detected; the code is a legitimate Go code generator that writes template output to files under a configured output folder. |
| boilingcore/templates.go | safe | No malicious patterns detected in the provided Go source code. |
| boilingcore/text_helpers.go | safe | Cleared by Jev triage; no further analysis needed |
| drivers/column.go | safe | Cleared by Jev triage; no further analysis needed |
| drivers/config.go | safe | No malicious patterns detected; the code is a straightforward configuration utility with type assertions and no network, filesystem, or process manipulation. |
| drivers/interface.go | safe | Cleared by Jev triage; no further analysis needed |
| drivers/keys.go | safe | Cleared by Jev triage; no further analysis needed |
| drivers/mocks/mock.go | safe | The code is a benign mock database driver implementation with no malicious patterns detected. |
| drivers/registration.go | safe | No malicious patterns detected |
| drivers/relationships.go | safe | Cleared by Jev triage; no further analysis needed |
| drivers/sqlboiler-mssql/driver/bindata.go | safe | No malicious patterns detected; this is standard go-bindata generated code for embedding template files. |
| drivers/sqlboiler-mssql/driver/mssql.go | safe | No malicious patterns detected: the code is a legitimate MSSQL driver for SQLBoiler with standard database operations and no exfiltration, credential harvesting, obfuscation, or backdoors. |
| drivers/sqlboiler-mssql/main.go | safe | Cleared by Jev triage; no further analysis needed |
Show 41 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| drivers/sqlboiler-mysql/driver/bindata.go | safe | No malicious patterns detected; this is a standard go-bindata generated file embedding template data, with no network calls, exfiltration, credential harvesting, obfuscated code, process spawning, or suspicious install/import-time behavior. |
| drivers/sqlboiler-mysql/driver/mysql.go | safe | This is a legitimate MySQL driver implementation for sqlboiler that performs standard database introspection queries with no malicious patterns detected. |
| drivers/sqlboiler-mysql/main.go | safe | Cleared by Jev triage; no further analysis needed |
| drivers/sqlboiler-psql/driver/bindata.go | safe | This is a standard go-bindata generated file that embeds gzipped template assets for the sqlboiler-psql driver, with no malicious patterns detected. |
| drivers/sqlboiler-psql/main.go | safe | Cleared by Jev triage; no further analysis needed |
| drivers/table.go | safe | Cleared by Jev triage; no further analysis needed |
| importers/imports.go | safe | Cleared by Jev triage; no further analysis needed |
| queries/eager_load.go | safe | No malicious patterns detected |
| queries/helpers.go | safe | Cleared by Jev triage; no further analysis needed |
| queries/qm/query_mods.go | safe | Cleared by Jev triage; no further analysis needed |
| queries/qmhelper/qmhelper.go | safe | Cleared by Jev triage; no further analysis needed |
| queries/query.go | safe | No malicious patterns detected in this SQL query builder code; it contains no exfiltration, credential harvesting, obfuscation, process spawning, or network activity. |
| queries/query_builders.go | safe | No malicious patterns such as exfiltration, credential harvesting, obfuscation, code execution, or network activity were found; the code is a legitimate SQL query builder with standard input validation. |
| queries/reflect.go | safe | No malicious patterns detected |
| randomize/random.go | safe | No malicious patterns detected; the code is a legitimate random data generation library for database testing. |
| randomize/randomize.go | safe | Cleared by Jev triage; no further analysis needed |
| strmangle/buf_pool.go | safe | Cleared by Jev triage; no further analysis needed |
| strmangle/inflect.go | safe | Cleared by Jev triage; no further analysis needed |
| strmangle/sets.go | safe | Cleared by Jev triage; no further analysis needed |
| strmangle/strmangle.go | safe | No malicious patterns detected in this string manipulation utility package. |
| types/array.go | safe | No malicious patterns detected; the code is a standard PostgreSQL array type implementation with no network, filesystem, process, or obfuscation concerns. |
| types/byte.go | safe | Cleared by Jev triage; no further analysis needed |
| types/decimal.go | safe | Cleared by Jev triage; no further analysis needed |
| types/hstore.go | safe | Cleared by Jev triage; no further analysis needed |
| types/json.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/box.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/circle.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/general.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/line.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/lseg.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/main.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/nullBox.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/nullCircle.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/nullLine.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/nullLseg.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/nullPath.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/nullPoint.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/nullPolygon.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/path.go | safe | No malicious patterns detected |
| types/pgeo/point.go | safe | Cleared by Jev triage; no further analysis needed |
| types/pgeo/polygon.go | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of github.com/thrasher-corp/sqlboiler
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| v1.0.1-0.20191001234224-71e17f37a85e | Needs review | 66 | Oct 5, 2026 |
Frequently asked questions
Is github.com/thrasher-corp/sqlboiler safe to use?
No confirmed malware was found in github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e, but the review flagged 5 medium, 12 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/thrasher-corp/sqlboiler contain malware?
No malware was identified in github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/thrasher-corp/sqlboiler checked?
Togoder Security downloaded the published Go package and had an AI model read its 66 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/thrasher-corp/sqlboiler together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/thrasher-corp/sqlboiler@v1.0.1-0.20191001234224-71e17f37a85e, cost nothing.