Summary
Togoder Security scanned the Go package google.golang.org/genproto/googleapis/api@v0.0.0-20260803160001-6ac0973c030d on Oct 5, 2026. An AI review of 44 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| annotations/annotations.pb.go | safe | No malicious patterns detected; the file is a standard protoc-gen-go generated file containing only protobuf descriptors and extension type registration. |
| annotations/client.pb.go | safe | No malicious patterns detected; this is standard protoc-generated Go code from Google's API annotations proto with only benign init registration logic. |
| annotations/field_behavior.pb.go | safe | Auto-generated protobuf Go code for google.api.FieldBehavior enum containing only standard protobuf registration code with no malicious patterns. |
| annotations/field_info.pb.go | safe | This is a standard generated Protocol Buffers Go file with no malicious patterns, no network activity, no process execution, and no credential or data exfiltration concerns. |
| annotations/http.pb.go | safe | No malicious patterns detected |
| annotations/resource.pb.go | safe | This is a standard protoc-gen-go generated file from Google's googleapis repository containing only protobuf message definitions, enums, and init logic with no malicious patterns detected. |
| annotations/routing.pb.go | safe | This is a standard protoc-gen-go generated file for Google's routing proto, containing only safe protobuf message definitions and no malicious patterns. |
| configchange/config_change.pb.go | safe | No malicious patterns detected; the file is standard protoc-gen-go generated code with no runtime network, filesystem, or process operations. |
| distribution/distribution.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file for Google's Distribution protobuf type with only benign initialization and reflection code. |
| error_reason/error_reason.pb.go | safe | No malicious patterns detected in this standard protobuf-generated Go enum file. |
| expr/conformance/v1alpha1/conformance_service.pb.go | safe | No malicious patterns detected |
| expr/v1alpha1/checked.pb.go | safe | No malicious patterns detected; this is standard protoc-gen-go generated code for CEL checked expression protobuf types with only benign imports, init registration, and no network, exec, or filesystem activity. |
| expr/v1alpha1/eval.pb.go | safe | Code is a standard protoc-gen-go generated file for Google API expression evaluation protobuf definitions with no malicious patterns detected. |
| expr/v1alpha1/explain.pb.go | safe | This is a standard protoc-gen-go generated file for the Google CEL Explain proto message containing only serialization, reflection, and descriptor registration code with no malicious patterns. |
| expr/v1alpha1/syntax.pb.go | safe | No malicious patterns detected in this protoc-gen-go generated code for the CEL syntax proto definitions. |
| expr/v1alpha1/value.pb.go | safe | This is a standard protobuf-generated Go file from Google's CEL (Common Expression Language) library with no malicious patterns detected. |
| expr/v1beta1/decl.pb.go | safe | No malicious patterns detected; the file is a standard protoc-gen-go generated Protocol Buffers declaration file from a legitimate Google package. |
| expr/v1beta1/eval.pb.go | safe | No malicious patterns detected |
| expr/v1beta1/expr.pb.go | safe | No malicious patterns detected |
| expr/v1beta1/source.pb.go | safe | This is standard generated protobuf Go code for the Google API expr v1beta1 source types, with no malicious patterns such as network exfiltration, environment harvesting, dynamic execution, or process spawning. |
| expr/v1beta1/value.pb.go | safe | No malicious patterns detected in this generated protobuf Go file from Google's CEL expression library. |
| httpbody/httpbody.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file for the google.api.HttpBody protobuf message with only benign registration and accessor code. |
| label/label.pb.go | safe | No malicious patterns detected |
| launch_stage.pb.go | safe | No malicious patterns detected; this is a standard, auto-generated protobuf Go file for an enum from the googleapis package with only an init() function that registers the file descriptor, no network, credential, obfuscation, or process-spawning behavior. |
| metric/metric.pb.go | safe | No malicious patterns detected; this is a standard protoc-generated Go file from google.golang.org/genproto with only declarative message/enum definitions and an init() that registers protobuf types. |
Show 19 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| monitoredres/monitored_resource.pb.go | safe | No malicious patterns detected |
| serviceconfig/auth.pb.go | safe | This is a standard protobuf-generated Go file for Google API authentication configuration, containing only data structures and serialization logic with no malicious patterns. |
| serviceconfig/backend.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file for Google API backend configuration with only declarative protobuf message definitions and standard init/registration code. |
| serviceconfig/billing.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file from the Google APIs serviceconfig package containing only serialization logic for billing configuration messages. |
| serviceconfig/consumer.pb.go | safe | This is a standard protoc-gen-go generated file containing only protobuf message definitions and serialization logic, with no malicious patterns detected. |
| serviceconfig/context.pb.go | safe | This is a standard protoc-gen-go generated file for google/api/context.proto containing only protobuf message definitions with no network, filesystem, process, or credential access patterns. |
| serviceconfig/control.pb.go | safe | No malicious patterns detected; this is a standard protoc-generated Go file for Google API Control protobuf with only safe descriptor/init boilerplate. |
| serviceconfig/documentation.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file containing only protobuf message definitions and reflection helpers. |
| serviceconfig/endpoint.pb.go | safe | This is a standard protoc-gen-go generated file defining the Endpoint message for the google.api service config; no malicious patterns detected. |
| serviceconfig/log.pb.go | safe | No malicious patterns detected in this protoc-generated Go file; it contains only standard protobuf serialization code with no network, filesystem, process, or credential access. |
| serviceconfig/logging.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file for Google API service configuration logging with no data exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| serviceconfig/monitoring.pb.go | safe | This is standard generated protobuf code from Google's API library containing only data structure definitions and serialization logic with no malicious patterns. |
| serviceconfig/policy.pb.go | safe | No malicious patterns detected; this is a standard protoc-gen-go generated file containing only protobuf message definitions and no executable logic beyond safe initialization. |
| serviceconfig/quota.pb.go | safe | This is a standard protoc-gen-go generated Protocol Buffers file containing only data structure definitions and reflection setup with no executable payloads, network calls, or suspicious patterns. |
| serviceconfig/service.pb.go | safe | This is a standard, machine-generated protobuf Go file from Google APIs with no malicious patterns, obfuscation, network calls, or dynamic code execution. |
| serviceconfig/source_info.pb.go | safe | Generated protobuf Go code containing only standard serialization logic; no malicious patterns detected |
| serviceconfig/system_parameter.pb.go | safe | This is a standard protoc-gen-go generated file containing only protobuf message definitions, getters, and descriptor registration with no malicious patterns, network calls, command execution, or install-time behavior. |
| serviceconfig/usage.pb.go | safe | This is a standard protoc-gen-go generated file with no malicious patterns, network calls, or suspicious behavior. |
| visibility/visibility.pb.go | safe | No malicious patterns detected in this protobuf-generated Go file from the official googleapis/genproto package. |
Frequently asked questions
Is google.golang.org/genproto/googleapis/api safe to use?
Our AI source review of google.golang.org/genproto/googleapis/api@v0.0.0-20260803160001-6ac0973c030d found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does google.golang.org/genproto/googleapis/api contain malware?
No malware was identified in google.golang.org/genproto/googleapis/api@v0.0.0-20260803160001-6ac0973c030d when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was google.golang.org/genproto/googleapis/api checked?
Togoder Security downloaded the published Go package and had an AI model read its 44 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan google.golang.org/genproto/googleapis/api together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in google.golang.org/genproto/googleapis/api@v0.0.0-20260803160001-6ac0973c030d, cost nothing.