Back to skill

Security audit

ADHD Sisterhood 晚确诊女性ADHD助手

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only ADHD education and support skill with disclosed medical boundaries and no hidden access or execution behavior.

Before installing, treat this as educational and peer-support style content, not medical care. Use it for learning, planning questions for clinicians, and practical coping strategies; do not use it to self-diagnose, change medication, interpret biomarker or genetic results, or replace a qualified medical professional.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The skill hard-codes a Chinese-speaking persona and response style without indicating that the user can choose another language. This can cause exclusion, misunderstanding, or unsafe communication if a user cannot adequately understand the output, especially in a health-adjacent support context where clarity and informed comprehension matter.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The content presents AI-assisted diagnosis methods, diagnostic accuracy figures, and consumer fNIRS/neurofeedback devices in a way that could encourage readers to rely on them for diagnosis or treatment adjustment. Although the file includes a general warning that medication decisions must be made by a psychiatrist, it does not clearly state that these AI tools and consumer devices are investigational, variably validated, and not substitutes for formal clinical diagnosis or treatment decisions.

Static analysis

No suspicious patterns detected.