segundo

Security checks across malware telemetry and agentic risk

Overview

This is a coherent personal notes CLI skill with expected local storage and optional cloud embeddings that users should understand before enabling.

Install the segundo CLI only from a trusted source, protect the ~/.segundo directory, avoid storing secrets or highly sensitive notes unless you accept the risk, and prefer local Ollama embeddings for private notes unless you are comfortable with cloud embedding processing and API-key use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly documents semantic search via Ollama or OpenAI and references use of an OpenAI API key, but it does not disclose that note content may be sent to an external embedding provider for processing. Because this tool is a 'second brain' for personal thoughts, notes, and recommendations, users may store sensitive information and reasonably assume local-only handling unless warned otherwise.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal