Summary
Togoder Security scanned the Go package golang.org/x/arch@v0.13.0 on Oct 5, 2026. An AI review of 72 source files produced 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
file system read
NPS-642622E9050E
The program opens and reads a PDF file provided as a command-line argument. This is expected behavior for the tool and does not indicate malicious intent.
file system write
NPS-3EF8EA6E6711
The program writes JSON output to standard output. This is expected behavior and not a security concern.
Potential unintended command execution
NPS-05D3D8ED9B42
The program reads a PDF file path from os.Args[1] and opens it with pdf.Open. While this is expected behavior for a CLI tool, if the binary is invoked with attacker-controlled arguments, it could lead to processing malicious PDFs, but there is no direct shell execution.
File system access
NPS-1C4A7E5F8E89
The program reads a PDF file specified by the user and writes output to stdout. This is within expected functionality and does not manipulate files outside the user-specified input.
Unused variable
NPS-C8079DF6B591
The variable jsFix is defined but unused, which is harmless but indicates leftover code. No security impact.
Unused function parameter
NPS-5AD25C2147F6
The function printTable has an unused parameter table and an unused import strconv via _ = strconv.Atoi. This is harmless.
Build-time execution
NPS-71714A799CE0
The file has a '//go:build ignore' directive, so it is not compiled into the package. It is intended to be run manually via 'go run util.go' for generating test cases, not at install or import time.
Process spawning
NPS-F522AB42F4C8
The code uses os/exec to run external tools (gcc, objdump, go run) for code generation. This is expected for a build-time test case generator and is not malicious.
Spawning processes or shell commands
NPS-3F27369EECA7
The code uses os/exec to spawn external processes (gcc, objdump, go run). While this is expected for a test case generator, it's a red flag that should be noted. The commands are invoked with hardcoded or derived arguments, and there is no evidence of command injection, but it's still a security concern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| s390x/s390xutil/util.go | medium | The code is a legitimate test case generator that spawns gcc, objdump, and go run, with no malicious patterns detected, but process spawning is present. |
| arm/armasm/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| arm/armasm/gnu.go | safe | Cleared by Jev triage; no further analysis needed |
| arm/armasm/inst.go | safe | Cleared by Jev triage; no further analysis needed |
| arm/armasm/plan9x.go | safe | Cleared by Jev triage; no further analysis needed |
| arm/armmap/map.go | safe | Cleared by Jev triage; no further analysis needed |
| arm/armspec/spec.go | safe | No malicious patterns detected; the code is a PDF parsing tool that reads a local file and outputs JSON. |
| arm/armspec/specmap.go | safe | Cleared by Jev triage; no further analysis needed |
| arm64/arm64asm/arg.go | safe | This file only contains constant definitions for ARM64 instruction argument types and extensive documentation comments; no executable code, network access, file system manipulation, or other malicious patterns are present. |
| arm64/arm64asm/condition.go | safe | Cleared by Jev triage; no further analysis needed |
| arm64/arm64asm/condition_util.go | safe | Cleared by Jev triage; no further analysis needed |
| arm64/arm64asm/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| arm64/arm64asm/gnu.go | safe | Cleared by Jev triage; no further analysis needed |
| arm64/arm64asm/inst.go | safe | Cleared by Jev triage; no further analysis needed |
| arm64/arm64asm/plan9x.go | safe | Cleared by Jev triage; no further analysis needed |
| arm64/arm64gen/sysreggen.go | safe | No malicious patterns detected; the code is a legitimate XML parser/generator for ARM64 system register encodings with no network, credential, or dynamic execution activity. |
| arm64/arm64spec/spec.go | safe | No malicious patterns detected |
| loong64/loong64asm/arg.go | safe | Cleared by Jev triage; no further analysis needed |
| loong64/loong64asm/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| loong64/loong64asm/gnu.go | safe | Cleared by Jev triage; no further analysis needed |
| loong64/loong64asm/inst.go | safe | Cleared by Jev triage; no further analysis needed |
| loong64/loong64asm/plan9x.go | safe | Cleared by Jev triage; no further analysis needed |
| loong64/loong64asm/tables.go | safe | Cleared by Jev triage; no further analysis needed |
| loong64/loong64spec/spec.go | safe | No malicious patterns detected; the code is a legitimate build-time tool that parses a PDF specification to generate Go instruction tables. |
| ppc64/ppc64asm/decode.go | safe | Cleared by Jev triage; no further analysis needed |
Show 47 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| ppc64/ppc64asm/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| ppc64/ppc64asm/field.go | safe | Cleared by Jev triage; no further analysis needed |
| ppc64/ppc64asm/gnu.go | safe | Cleared by Jev triage; no further analysis needed |
| ppc64/ppc64asm/inst.go | safe | Cleared by Jev triage; no further analysis needed |
| ppc64/ppc64asm/plan9.go | safe | Cleared by Jev triage; no further analysis needed |
| ppc64/ppc64map/map.go | safe | This is a legitimate Go code generator from the official golang.org/x/arch repository that parses a CSV file and produces opcode tables; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, network access, or process spawning are present. |
| ppc64/ppc64spec/spec.go | safe | The code is a legitimate PDF parsing tool from the Go standard library, with no malicious patterns such as data exfiltration, credential harvesting, or backdoors detected. |
| ppc64/ppc64util/util.go | safe | The file is a legitimate build-time utility for generating ppc64 test cases and contains no malicious patterns. |
| riscv64/riscv64asm/arg.go | safe | Cleared by Jev triage; no further analysis needed |
| riscv64/riscv64asm/csr_string.go | safe | No malicious patterns detected; this is a standard auto-generated stringer file for RISC-V CSR constants with no I/O, network, process, or dynamic execution capabilities. |
| riscv64/riscv64asm/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| riscv64/riscv64asm/gnu.go | safe | Cleared by Jev triage; no further analysis needed |
| riscv64/riscv64asm/inst.go | safe | Cleared by Jev triage; no further analysis needed |
| riscv64/riscv64asm/plan9x.go | safe | Cleared by Jev triage; no further analysis needed |
| riscv64/riscv64asm/tables.go | safe | No malicious patterns detected; the file is a generated RISC-V instruction table containing only constant definitions, string mappings, and static struct literals. |
| riscv64/riscv64spec/spec.go | safe | No malicious patterns detected |
| s390x/s390xasm/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| s390x/s390xasm/field.go | safe | Cleared by Jev triage; no further analysis needed |
| s390x/s390xasm/gnu.go | safe | Cleared by Jev triage; no further analysis needed |
| s390x/s390xasm/inst.go | safe | Cleared by Jev triage; no further analysis needed |
| s390x/s390xasm/plan9.go | safe | Cleared by Jev triage; no further analysis needed |
| s390x/s390xmap/map.go | safe | Cleared by Jev triage; no further analysis needed |
| s390x/s390xspec/spec.go | safe | The code is a benign Go utility for parsing PDF documentation to generate instruction encoding CSVs, with no malicious patterns or security concerns. |
| x86/x86asm/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86asm/gnu.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86asm/inst.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86asm/intel.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86asm/plan9x.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86avxgen/decode.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86avxgen/generate.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86avxgen/instruction.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86avxgen/main.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86avxgen/print.go | safe | No malicious patterns detected; this is a standard Go code generator for x86 AVX instruction tables using text/template and go/format without any network, filesystem, or process execution concerns. |
| x86/x86csv/reader.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86csv/x86csv.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86map/map.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86spec/cleanup.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86spec/format.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/x86spec/parse.go | safe | No malicious patterns detected; the code is a benign PDF parser for generating x86 instruction specifications from Intel manual PDFs. |
| x86/x86spec/spec.go | safe | No malicious patterns detected |
| x86/xeddata/database.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/xeddata/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/xeddata/object.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/xeddata/operand.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/xeddata/pattern_set.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/xeddata/reader.go | safe | Cleared by Jev triage; no further analysis needed |
| x86/xeddata/xeddata.go | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is golang.org/x/arch safe to use?
No confirmed malware was found in golang.org/x/arch@v0.13.0, but the review flagged 9 low severity findings for risky patterns worth checking before you rely on it.
Does golang.org/x/arch contain malware?
No malware was identified in golang.org/x/arch@v0.13.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was golang.org/x/arch checked?
Togoder Security downloaded the published Go package and had an AI model read its 72 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan golang.org/x/arch together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in golang.org/x/arch@v0.13.0, cost nothing.