Togoder security

Go package security report

golang.org/x/arch Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v0.13.0 Files reviewed 72 Size 2.3 MB Scanned

Summary

Togoder Security scanned the Go package golang.org/x/arch@v0.13.0 on Oct 5, 2026. An AI review of 72 source files produced 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
9
low

Findings 9

low

file system read

NPS-642622E9050E

The program opens and reads a PDF file provided as a command-line argument. This is expected behavior for the tool and does not indicate malicious intent.

arm/armspec/spec.go:61
low

file system write

NPS-3EF8EA6E6711

The program writes JSON output to standard output. This is expected behavior and not a security concern.

arm/armspec/spec.go:76
low

Potential unintended command execution

NPS-05D3D8ED9B42

The program reads a PDF file path from os.Args[1] and opens it with pdf.Open. While this is expected behavior for a CLI tool, if the binary is invoked with attacker-controlled arguments, it could lead to processing malicious PDFs, but there is no direct shell execution.

ppc64/ppc64spec/spec.go:51
low

File system access

NPS-1C4A7E5F8E89

The program reads a PDF file specified by the user and writes output to stdout. This is within expected functionality and does not manipulate files outside the user-specified input.

ppc64/ppc64spec/spec.go:51
low

Unused variable

NPS-C8079DF6B591

The variable jsFix is defined but unused, which is harmless but indicates leftover code. No security impact.

ppc64/ppc64spec/spec.go:513
low

Unused function parameter

NPS-5AD25C2147F6

The function printTable has an unused parameter table and an unused import strconv via _ = strconv.Atoi. This is harmless.

ppc64/ppc64spec/spec.go:518
low

Build-time execution

NPS-71714A799CE0

The file has a '//go:build ignore' directive, so it is not compiled into the package. It is intended to be run manually via 'go run util.go' for generating test cases, not at install or import time.

ppc64/ppc64util/util.go:7
low

Process spawning

NPS-F522AB42F4C8

The code uses os/exec to run external tools (gcc, objdump, go run) for code generation. This is expected for a build-time test case generator and is not malicious.

ppc64/ppc64util/util.go:84
low

Spawning processes or shell commands

NPS-3F27369EECA7

The code uses os/exec to spawn external processes (gcc, objdump, go run). While this is expected for a test case generator, it's a red flag that should be noted. The commands are invoked with hardcoded or derived arguments, and there is no evidence of command injection, but it's still a security concern.

s390x/s390xutil/util.go

Files reviewed

FileVerdictWhat the reviewer saw
s390x/s390xutil/util.go medium The code is a legitimate test case generator that spawns gcc, objdump, and go run, with no malicious patterns detected, but process spawning is present.
arm/armasm/decode.go safe Cleared by Jev triage; no further analysis needed
arm/armasm/gnu.go safe Cleared by Jev triage; no further analysis needed
arm/armasm/inst.go safe Cleared by Jev triage; no further analysis needed
arm/armasm/plan9x.go safe Cleared by Jev triage; no further analysis needed
arm/armmap/map.go safe Cleared by Jev triage; no further analysis needed
arm/armspec/spec.go safe No malicious patterns detected; the code is a PDF parsing tool that reads a local file and outputs JSON.
arm/armspec/specmap.go safe Cleared by Jev triage; no further analysis needed
arm64/arm64asm/arg.go safe This file only contains constant definitions for ARM64 instruction argument types and extensive documentation comments; no executable code, network access, file system manipulation, or other malicious patterns are present.
arm64/arm64asm/condition.go safe Cleared by Jev triage; no further analysis needed
arm64/arm64asm/condition_util.go safe Cleared by Jev triage; no further analysis needed
arm64/arm64asm/decode.go safe Cleared by Jev triage; no further analysis needed
arm64/arm64asm/gnu.go safe Cleared by Jev triage; no further analysis needed
arm64/arm64asm/inst.go safe Cleared by Jev triage; no further analysis needed
arm64/arm64asm/plan9x.go safe Cleared by Jev triage; no further analysis needed
arm64/arm64gen/sysreggen.go safe No malicious patterns detected; the code is a legitimate XML parser/generator for ARM64 system register encodings with no network, credential, or dynamic execution activity.
arm64/arm64spec/spec.go safe No malicious patterns detected
loong64/loong64asm/arg.go safe Cleared by Jev triage; no further analysis needed
loong64/loong64asm/decode.go safe Cleared by Jev triage; no further analysis needed
loong64/loong64asm/gnu.go safe Cleared by Jev triage; no further analysis needed
loong64/loong64asm/inst.go safe Cleared by Jev triage; no further analysis needed
loong64/loong64asm/plan9x.go safe Cleared by Jev triage; no further analysis needed
loong64/loong64asm/tables.go safe Cleared by Jev triage; no further analysis needed
loong64/loong64spec/spec.go safe No malicious patterns detected; the code is a legitimate build-time tool that parses a PDF specification to generate Go instruction tables.
ppc64/ppc64asm/decode.go safe Cleared by Jev triage; no further analysis needed
Show 47 more files
FileVerdictWhat the reviewer saw
ppc64/ppc64asm/doc.go safe Cleared by Jev triage; no further analysis needed
ppc64/ppc64asm/field.go safe Cleared by Jev triage; no further analysis needed
ppc64/ppc64asm/gnu.go safe Cleared by Jev triage; no further analysis needed
ppc64/ppc64asm/inst.go safe Cleared by Jev triage; no further analysis needed
ppc64/ppc64asm/plan9.go safe Cleared by Jev triage; no further analysis needed
ppc64/ppc64map/map.go safe This is a legitimate Go code generator from the official golang.org/x/arch repository that parses a CSV file and produces opcode tables; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, network access, or process spawning are present.
ppc64/ppc64spec/spec.go safe The code is a legitimate PDF parsing tool from the Go standard library, with no malicious patterns such as data exfiltration, credential harvesting, or backdoors detected.
ppc64/ppc64util/util.go safe The file is a legitimate build-time utility for generating ppc64 test cases and contains no malicious patterns.
riscv64/riscv64asm/arg.go safe Cleared by Jev triage; no further analysis needed
riscv64/riscv64asm/csr_string.go safe No malicious patterns detected; this is a standard auto-generated stringer file for RISC-V CSR constants with no I/O, network, process, or dynamic execution capabilities.
riscv64/riscv64asm/decode.go safe Cleared by Jev triage; no further analysis needed
riscv64/riscv64asm/gnu.go safe Cleared by Jev triage; no further analysis needed
riscv64/riscv64asm/inst.go safe Cleared by Jev triage; no further analysis needed
riscv64/riscv64asm/plan9x.go safe Cleared by Jev triage; no further analysis needed
riscv64/riscv64asm/tables.go safe No malicious patterns detected; the file is a generated RISC-V instruction table containing only constant definitions, string mappings, and static struct literals.
riscv64/riscv64spec/spec.go safe No malicious patterns detected
s390x/s390xasm/decode.go safe Cleared by Jev triage; no further analysis needed
s390x/s390xasm/field.go safe Cleared by Jev triage; no further analysis needed
s390x/s390xasm/gnu.go safe Cleared by Jev triage; no further analysis needed
s390x/s390xasm/inst.go safe Cleared by Jev triage; no further analysis needed
s390x/s390xasm/plan9.go safe Cleared by Jev triage; no further analysis needed
s390x/s390xmap/map.go safe Cleared by Jev triage; no further analysis needed
s390x/s390xspec/spec.go safe The code is a benign Go utility for parsing PDF documentation to generate instruction encoding CSVs, with no malicious patterns or security concerns.
x86/x86asm/decode.go safe Cleared by Jev triage; no further analysis needed
x86/x86asm/gnu.go safe Cleared by Jev triage; no further analysis needed
x86/x86asm/inst.go safe Cleared by Jev triage; no further analysis needed
x86/x86asm/intel.go safe Cleared by Jev triage; no further analysis needed
x86/x86asm/plan9x.go safe Cleared by Jev triage; no further analysis needed
x86/x86avxgen/decode.go safe Cleared by Jev triage; no further analysis needed
x86/x86avxgen/generate.go safe Cleared by Jev triage; no further analysis needed
x86/x86avxgen/instruction.go safe Cleared by Jev triage; no further analysis needed
x86/x86avxgen/main.go safe Cleared by Jev triage; no further analysis needed
x86/x86avxgen/print.go safe No malicious patterns detected; this is a standard Go code generator for x86 AVX instruction tables using text/template and go/format without any network, filesystem, or process execution concerns.
x86/x86csv/reader.go safe Cleared by Jev triage; no further analysis needed
x86/x86csv/x86csv.go safe Cleared by Jev triage; no further analysis needed
x86/x86map/map.go safe Cleared by Jev triage; no further analysis needed
x86/x86spec/cleanup.go safe Cleared by Jev triage; no further analysis needed
x86/x86spec/format.go safe Cleared by Jev triage; no further analysis needed
x86/x86spec/parse.go safe No malicious patterns detected; the code is a benign PDF parser for generating x86 instruction specifications from Intel manual PDFs.
x86/x86spec/spec.go safe No malicious patterns detected
x86/xeddata/database.go safe Cleared by Jev triage; no further analysis needed
x86/xeddata/doc.go safe Cleared by Jev triage; no further analysis needed
x86/xeddata/object.go safe Cleared by Jev triage; no further analysis needed
x86/xeddata/operand.go safe Cleared by Jev triage; no further analysis needed
x86/xeddata/pattern_set.go safe Cleared by Jev triage; no further analysis needed
x86/xeddata/reader.go safe Cleared by Jev triage; no further analysis needed
x86/xeddata/xeddata.go safe Cleared by Jev triage; no further analysis needed

Scanned versions of golang.org/x/arch

VersionVerdictFilesScanned
v0.13.0 Needs review 72 Oct 5, 2026

Frequently asked questions

Is golang.org/x/arch safe to use?

No confirmed malware was found in golang.org/x/arch@v0.13.0, but the review flagged 9 low severity findings for risky patterns worth checking before you rely on it.

Does golang.org/x/arch contain malware?

No malware was identified in golang.org/x/arch@v0.13.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was golang.org/x/arch checked?

Togoder Security downloaded the published Go package and had an AI model read its 72 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan golang.org/x/arch together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in golang.org/x/arch@v0.13.0, cost nothing.

Related security reports