Back to skill

Security audit

segundo

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent personal notes CLI guide with expected local storage and optional cloud embeddings, but users should treat stored notes and OpenAI embedding setup as private-data decisions.

Before installing, confirm you are comfortable storing personal notes under ~/.segundo and using any configured brain path. Prefer local Ollama embeddings for sensitive memories, and only configure OpenAI embeddings if you are comfortable sending note/search data to a cloud provider. Use delete carefully because the artifact does not document recovery behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents a delete command that permanently removes memories but does not warn users that the action is destructive or whether recovery is possible. In an agent-mediated context, this increases the risk of accidental data loss because a user or downstream automation may invoke deletion without understanding the consequence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The semantic search setup mentions OpenAI support but does not clearly warn that configuring a cloud embedding provider may transmit stored memory content or search queries to a third party. Because this tool stores personal notes and 'second brain' content, users may unknowingly expose sensitive data externally, making the omission materially risky in this skill context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.