second-brain — security grade SAFE, quality 64/100

Security audit verdict: SAFE · quality 64/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by mshtawythug · MCP Server · ★ 14

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is second-brain safe to install? View the security audit →

About second-brain

Local-first personal knowledge base CLI — hybrid FTS + pgvector search, a GraphRAG entity graph, and LLM enrichment over your notes, transcripts, Slack & Gmail. Runs fully local on Ollama (no cloud, no API keys); queryable by any AI agent through the built-in MCP server. Postgres-backed, publishes an Obsidian-style Quartz wiki.

cliembeddingsgraphraghybrid-searchknowledge-baselocal-ailocal-firstmcpmcp-servernote-taking

Quick Facts

Stars14
Forks1
LanguagePython
CategoryMCP Server
LicenseMIT
Quality Score64.0126810502136/100
Last Updated2026-09-29
Created2026-05-14
Platformscli, mcp, python
Est. Tokens~17k

Compatible Skills

These tools work well together with second-brain for enhanced workflows:

  • omt — semantic(0.18)+complementary+shared_fw(ollama)+same_lang+similar_pop+shared_platform (64%)
  • llm-wiki-newsroom — semantic(0.39)+complementary+same_lang+similar_pop+shared_platform (64%)

second-brain alternative? Top 6 similar tools

Looking for a second-brain alternative? If you're comparing second-brain with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • ChatCrystal by ZengLiangYi · ⭐ 58

    Local-first AI PKM for coding conversations: import Claude Code/Cursor/Codex, distill notes, semantic search,

  • mychatarchive by 1ch1n · ⭐ 65

    Local-first AI memory archive. Import ChatGPT, Claude, and Grok exports, generate semantic embeddings, and sea

  • devrag by tomohiro-owada · ⭐ 63

    Markdown vector search MCP server for Claude Code. Natural language search for markdown files using multilingu

  • codebase-context by PatrickSys · ⭐ 61

    Codebase Context gives AI agents understanding of your codebase through semantic code search, team conventions

  • lilbee by tobocop2 · ⭐ 61

    The whole local AI stack in one executable: it runs and manages local AI models across every GPU, and it's a s

  • brain-mcp by mordechaipotash · ⭐ 67

    Local-first AI memory MCP server — query your ChatGPT, Claude Code, Cursor & Codex history from any LLM. DuckD

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is second-brain?

second-brain is Local-first personal knowledge base CLI — hybrid FTS + pgvector search, a GraphRAG entity graph, and LLM enrichment over your notes, transcripts, Slack & Gmail. Runs fully local on Ollama (no cloud, n. It is categorized as a MCP Server with 14 GitHub stars.

What programming language is second-brain written in?

second-brain is primarily written in Python. It covers topics such as cli, embeddings, graphrag.

How do I install or use second-brain?

You can find installation instructions and usage details in the second-brain GitHub repository at github.com/mshtawythug/second-brain. The project has 14 stars and 1 forks, indicating an active community.

What license does second-brain use?

second-brain is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to second-brain?

The top alternatives to second-brain on Agent Skills Hub include ChatCrystal, mychatarchive, devrag. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools