Back to skill

Security audit

ADHD Assistant

Security checks across malware telemetry and agentic risk

Overview

This skill appears non-malicious, but it can steer broad productivity requests into ADHD-focused support and remember sensitive ADHD or treatment details without clear opt-in controls.

Review before installing. Use it only if you are comfortable with ADHD-specific framing and with the agent potentially storing health-adjacent details. Avoid saving diagnosis, medication, therapy, or emotional-sensitivity information unless you have clear memory controls to inspect, edit, and delete it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation rules and trigger phrases are broad enough to match many ordinary productivity or emotional-support conversations, which can cause the skill to be invoked when the user did not intend to engage an ADHD-focused workflow. In this context, unintended invocation is risky because the skill also steers toward memory, reminders, and mental-health-adjacent framing, increasing the chance of collecting sensitive information or giving condition-specific guidance without clear user consent.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill explicitly proposes learning and storing sensitive mental-health-related information, including ADHD status, treatment context, behavioral pitfalls, and preferences, and elsewhere supports writing plans and notes to memory/files. Without clear user-facing notice, minimization, and explicit opt-in, this creates a privacy and data-handling vulnerability that could expose sensitive health-related data or retain more information than the user expects.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.