Back to skill

Security audit

Brainhack — ADHD Sidekick

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent and not malware, but it should be reviewed because it persistently stores sensitive ADHD and emotional data and enables proactive outreach without enough consent, retention, or control details.

Install only if you are comfortable with an ADHD support agent remembering personal profile details, moods, routines, triggers, open tasks, and session summaries. Before use, configure memory and proactive messages explicitly, avoid sharing highly sensitive details over Telegram or WhatsApp unless you accept those platforms' privacy model, and require confirmation before connecting calendars or task apps.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (37)

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The file explicitly instructs the agent to send an unprompted check-in message via cron or heartbeat after 7+ days of inactivity. That creates autonomous outreach behavior not clearly bounded by explicit user opt-in or consent, which can surprise users and expand the agent's role from reactive assistant to persistent monitor.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to store and analyze longitudinal crisis-pattern data in MEMORY.md, including trigger words and signals associated with future meltdowns. Even if intended to improve support, this expands the agent from immediate triage into ongoing mental-health profiling without clear consent, retention limits, or privacy safeguards, which creates a meaningful sensitivity and misuse risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The proactive outreach flow is user-impacting behavior, but the file provides no user-facing warning that the system may contact them without a prompt. In a mental-health-adjacent ADHD support context, unexpected outreach can feel invasive and may reveal sensitive assistant usage to others who can see the user's device or messaging history.

Missing User Warnings

High
Confidence
98% confidence
Finding
The memory design stores mood baseline, open loops, focus area, routines, emotional state, and behavioral patterns across sessions without any visible notice, consent, or retention transparency. This is sensitive personal profiling data, and persisting it silently increases privacy risk, potential misuse, and user deception about how much of their emotional history is being retained.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The README states that the router maps everything the user says to a skill, which implies overly broad activation and insufficient boundary controls. In a messaging-based assistant handling emotional support, planning, and memory, this can cause unintended routing of sensitive, off-topic, or safety-critical user input into inappropriate automation paths, increasing the chance of privacy leakage, unsafe advice, or manipulation of agent behavior.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README advertises persistent memory and learned user patterns but does not disclose retention limits, consent, storage practices, or privacy risks. Because this skill is designed for ADHD support and may collect sensitive behavioral, emotional, and daily-life information through Telegram or WhatsApp, undisclosed long-term storage materially increases the risk of privacy harm, profiling, and unauthorized exposure of intimate user data.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The routing table uses many natural-language triggers that are broad, overlapping, and emotionally loaded, which can cause the agent to invoke the wrong skill without clear confirmation. In a mental-health-adjacent ADHD support context, misrouting can be harmful because a user expressing distress, planning needs, or casual phrases may be pushed into an unsuitable flow, reducing trust or giving inappropriate support at a sensitive moment.

Vague Triggers

Low
Confidence
81% confidence
Finding
The fallback opener is generic and there is no explicit guard preventing the system from interpreting the user's answer or the fallback itself as an immediate routing trigger without sufficient context. This creates a smaller but real risk of accidental skill activation, especially in a router that already relies heavily on broad conversational cues.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly states it will populate USER.md during onboarding and accumulate patterns in MEMORY.md over time, which implies storage of personal and behavioral data. Because this is a mental-health/ADHD-focused assistant, the stored information is likely sensitive, and the absence of any notice about retention, handling, or user consent creates a meaningful privacy risk.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill promotes use through Telegram or WhatsApp but does not disclose that user conversations will transit third-party messaging platforms with their own privacy and security characteristics. Given the assistant’s focus on ADHD, overwhelm, and emotional support, users may share sensitive personal or mental-health information without understanding the additional exposure to external platform providers.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This profile explicitly solicits sensitive health-related data, including ADHD status and medication schedule, but provides no clear notice about sensitivity, storage, retention, sharing, or that disclosure is optional. In a conversational support skill delivered over chat apps, users may overshare highly sensitive personal data without informed consent, increasing privacy, misuse, and compliance risk.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The onboarding flow is designed to feel like an informal chat, which can lower a user's guard while eliciting mental-health and behavioral profile information. Because it lacks a clear privacy, retention, and consent warning at the point of collection, users may not realize they are disclosing sensitive data into a persisted profile or third-party messaging environment.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The document instructs the agent to use a user's medication status from USER.md to alter behavior, which is health-related personalization based on sensitive data. Even if intended to improve support, this creates a privacy and consent risk because the file does not require explicit user opt-in, limit usage, or describe safeguards for handling medical information.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The guidance says the agent may schedule appointments directly and add routine blocks/tasks when tools are connected, but it does not require explicit per-action user confirmation, preview, or clear disclosure before modifying external systems. In a messaging-based ADHD assistant context, that is risky because users may interpret suggestions as conversational support while the agent performs real calendar/task mutations, leading to unwanted appointments, reminder spam, or integrity issues in personal planning data.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The cron-based morning briefs, evening check-ins, and recurring reminders describe proactive outbound messaging without any documented consent, opt-in, frequency controls, or privacy notice. In Telegram/WhatsApp, unsolicited or overly persistent messages can expose sensitive routines, appointments, or mental-health-related coaching context to anyone with access to the device, and can also create harassment or trust/safety issues if reminders are misconfigured.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger conditions are broad enough to activate on many ordinary statements, which can cause the agent to enter this skill in contexts the user did not intend. In a coaching skill that pushes action, reminders, and backlog management, over-triggering increases the chance of collecting or acting on sensitive life-admin details without clear user consent or relevance.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill instructs the agent to maintain a persistent MEMORY.md backlog of unfinished adulting tasks without notifying the user or obtaining consent. Because these tasks may include bills, appointments, paperwork, and other sensitive personal matters, silent persistence creates privacy and data-handling risk and can expose more personal context than the user expected.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill directs the agent to record task details, timing, completion status, and notes in MEMORY.md without requiring notice or consent. In an ADHD-support context, those notes can easily contain sensitive personal, health-adjacent, work, or emotional information, creating a privacy risk through silent retention and later reuse.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger conditions are broad enough to activate on ordinary long-form or emotionally expressive messages without a clear user request to invoke this skill. In a multi-skill agent, that can cause unintended routing and premature restructuring of user input, which may override user intent, mishandle sensitive context, or suppress a more appropriate safety-aware skill.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger conditions are broad enough that the skill could activate during ordinary conversation, especially with vague phrases like an evening message or end of a long session. In this context, unintended invocation is mainly a safety and UX issue, but it becomes more sensitive because the skill handles emotional check-ins and may proceed to log personal state without an explicit opt-in at activation time.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to write mood scores, wins, open loops, and a 7-day emotional baseline to MEMORY.md, but it provides no user-facing notice or consent mechanism for storing this sensitive personal data. Because the content includes emotional state and behavioral patterns, silent retention increases privacy risk and can expose intimate mental-health-adjacent information beyond what a user reasonably expects from a casual check-in.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly defines scheduled outreach, default send times, and adaptive nudges, but the file does not require explicit opt-in before proactive messaging begins. Although onboarding suggests asking the user about morning check-ins, the later default behavior of 9am/8pm local outreach means unprompted contact could occur without clear prior consent or a strong warning about persistent messaging behavior.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger includes a broad default activation on a user's first morning message and vague phrases like 'help me figure out today,' which can match ordinary conversation not specifically requesting this skill. In an agent pack with many skills, this increases the chance of unintended routing, causing the agent to apply planning behavior when the user meant something else or exposing contextual data such as memory or calendar-derived planning unnecessarily.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The instruction to log date, trigger words, and what helped into MEMORY.md involves storing highly sensitive mental-health crisis data without any user-facing notice, consent flow, or minimization guidance. Because this concerns acute emotional distress and inferred psychological state, undisclosed persistence materially increases privacy harm if accessed, reused, or retained longer than expected.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly directs the agent to write adherence-tracking data to MEMORY.md without any guardrail about user consent, data minimization, or what information is appropriate to persist. In a chat-based ADHD support context, this can lead to storage of sensitive behavioral or health-adjacent personal data, creating privacy risk and unwanted long-term profiling.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.