Back to skill

Security audit

ADHD Daily Planner

Security checks for vulnerabilities and agentic risk

Overview

This is a plain Markdown ADHD planning skill with no code execution or persistence, but users should treat its medication-related templates as non-medical self-tracking only.

Before installing, understand that this skill is a planning and self-management aid, not clinical ADHD treatment. Use the medication sections only to track observations or prepare questions for a qualified clinician; do not start, stop, skip, or adjust medication based on the skill's templates alone.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
- Low-stakes tasks only
- No major decisions

**The key**: Don't judge bad days. They're part of the pattern.

## Tools That Actually Help

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description broadly states that the skill provides planning and executive-function support for ADHD without specifying when it should or should not be invoked. In a manifest file context, this kind of open-ended capability description can overlap with many everyday planning or support requests and lacks negative examples or scope boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file includes 'Medication management' as a dopamine-supporting practice and broadly encourages self-directed behavior changes, but it does not include any caution to use medication only as prescribed or to consult a qualified clinician for medication-related concerns. In a mental health/ADHD support skill, omission of that boundary can normalize unsupervised medication adjustment or overgeneralized health advice, which may lead some users to make unsafe decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The medication section includes tracking and 'Tomorrow adjustment needed? Y/N' language without an explicit warning to consult a licensed clinician before changing dose, timing, or regimen. In a mental-health-adjacent ADHD planning skill, users may interpret this as actionable self-management advice and make unsafe medication changes based on subjective daily observations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.