Back to skill

Security audit

ADHD Founder Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a local ADHD planning skill that saves user-entered plans and reflections to local Markdown files, with some usability and privacy notes but no evidence of hidden or malicious behavior.

Before installing, understand that this planner stores your task lists, reflections, wins, blockers, and energy notes locally under ~/.openclaw/skills/adhd-daily-planner. Avoid entering highly sensitive information unless you are comfortable keeping it in local Markdown files, and keep exact calendar times with alarms for fixed commitments even though the planner encourages relative time blocks for flexible work.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/plan.sh:552
Finding

Regular Expression Injection in Task Completion Logic

Content
View full analysis
/dev/null; then # Escape sed special chars in task name TASK_SED=$(printf '%s' "$TASK" | sed 's/[&/\]/\\&/g') sed -i.bak "s/\[ \] ${TASK_SED}/[x] ${TASK_SED}/" "$TODAY_FILE" rm -f "${TODAY_FILE}.bak" echo "✅ Marked complete: $TASK" else # Add to wins section echo "" >> "$TODAY_FILE" echo "- × $TASK (added retroactively)" >> "$TODAY_FILE" fi ``` ### Technical Analysis The `done` command accepts user-controlled task text and incorporates it into a `sed` basic regular expression. The escaping operation only attempts to handle `&`, `/`, and `\`. It does not escape regular-expression metacharacters such as: - `.` - `*` - `[` - `]` - `^` - `$` The initial `grep -Fq` check treats the task as a fixed string, but the subsequent `sed` command interprets the same value as a regular expression. Consequently, the validation and modification operations use different matching semantics. For example, if the planner contains both of the following tasks: ```markdown - [ ] a.b - [ ] axb ``` Running: ```bash ./scripts/plan.sh done 'a.b' ``` passes the fixed-string check because the literal task `a.b` exists. In the `sed` expression, however, `.` matches any character. Both task lines can therefore match and be modified. Because the user value is also used as replacement text, the second task may additionally be rewritten as `a.b`, causing further data corruption. Malformed expressions involving brackets or other operators may also cause `sed` to fail. Since the script uses `set -e`, such an error can terminate the command unexpectedly. This flaw does not provide shell command execution because the task value remains inside a quoted shell expansion and is not evaluated as shell syntax. The vulnerabil ...[truncated 1314 chars]
Remediation
View remediation
"$tmp_file" mv -- "$tmp_file" "$TODAY_FILE" trap - EXIT ``` Additional hardening measures: 1. Match the complete task line rather than a substring to prevent ambiguous updates. 2. Modify only the first exact match unless duplicate-task behavior is explicitly defined. 3. Create temporary files in the destination directory so the final rename remains atomic. 4. Use `mktemp` rather than a predictable `.bak` filename. 5. Install a cleanup trap so temporary files are removed after errors or interruptions. 6. Add regression tests using task names containing `.`, `*`, `[`, `]`, `^`, `$`, `/`, `&`, and backslashes. 7. If `sed` must be retained, independently escape every basic-regex metacharacter in the search value and every replacement metacharacter in the replacement value. Exact string processing remains preferable. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill declares many broad natural-language triggers such as 'Plan my day', 'What should I work on today?', and general mentions of productivity concepts. This can cause the skill to activate during ordinary conversation where the user did not explicitly intend to invoke it, creating prompt-scope confusion and increasing the chance that unrelated user input is steered into this skill's workflow or adjacent promotional content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This guidance strongly promotes avoiding exact clock times and, in the flagged section, does not clearly warn that fixed commitments like appointments, meetings, medication, departures, and deadlines still require precise scheduling. In an ADHD-focused planning skill, users may over-apply the 'no clock times' rule and miss time-sensitive obligations, especially because the content is framed as a general solution to time blindness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The README includes natural-language branding that foregrounds a specific national/locale framing. While mild, this can be read as imposing a locale-specific positioning without offering user choice or justification tied to the skill's function.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly documents persistent storage of daily logs, monthly overviews, and collections under the user's home directory, but does not warn users that potentially sensitive mental-health, productivity, and personal notes will be retained on disk. In the context of an ADHD planning skill, these records can contain intimate personal data, so lack of disclosure increases privacy risk even if storage is local and expected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This shell script stores potentially sensitive personal productivity notes, reflections, and task lists in markdown files in ~/.openclaw/skills/adhd-daily-planner. While file persistence is central to the skill's purpose, the code does not clearly disclose at the point of collection that entered content will be saved on disk in a persistent location.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.