PyPI · pypi.org
secondbrain-os
Py Runtime Dynamic Dangerous Import: Dynamic __import__('os') — reflection bypass for static checks.
Why PkgRadar flagged 0.5.1
| Severity | Signal | Evidence |
|---|---|---|
| high | Py Runtime Dynamic Dangerous Import | Dynamic __import__('os') — reflection bypass for static checks. · secondbrain_os-0.5.1/brain/serve/dashboard.py |
| high | Py Runtime Base64 Decode | base64/hex decode combined with exec/subprocess — classic obfuscated payload pattern. · secondbrain_os-0.5.1/brain/serve/routers/content.py |
| medium | Credential file access | matched "aws_access_key" · secondbrain_os-0.5.1/brain/providers/bedrock_converse.py |
| medium | Credential file access | matched "AWS_ACCESS_KEY" · secondbrain_os-0.5.1/brain/providers/setup_hints.py |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
0.5.1 | High risk | 90 | 2026-06-01 |
0.5.0 | High risk | 90 | 2026-06-01 |
Block this in CI
pkgradar gate --ecosystem pypi secondbrain-os==0.5.1