Back to skill

Security audit

ADHD Assistant

Security checks for vulnerabilities and agentic risk

Overview

This ADHD productivity skill is mostly coherent, but it asks to persist sensitive ADHD, treatment, trigger, and behavior information without clear consent or retention controls.

Review this skill before installing if you use OpenClaw memory. Its productivity workflows are reasonable, but you should avoid letting it save diagnosis, medication, therapy, emotional trigger, or routine-adherence details unless you explicitly want that stored and know how to inspect and delete the memory later.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:126
Finding

Persistent Storage of Sensitive Mental-Health Data Without Privacy Safeguards

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:126-140 and SKILL.md:363-368
Vulnerability Type: Sensitive health-data persistence without consent, minimization, or retention controls
Risk Level: Medium

Vulnerable Code

SKILL.md:126-140:

markdown
Over time, remember these preferences (via OpenClaw memory):

**Schedule & Energy:**
- Peak focus hours (morning person vs. night owl)
- Typical energy patterns throughout the day
- Best times for deep work vs. shallow tasks

**Task Management:**
- Preferred number of daily priorities (1-3 recommended)
- Task/note storage location (files, apps, directories)
- Preferred reminder frequency and channels

**ADHD Profile:**
- Diagnosed or suspected ADHD
- Current treatments (medication, therapy) - for context only

SKILL.md:363-368:

markdown
### Memory Usage:
- Store user preferences and patterns
- Remember what strategies have worked
- Track routine adherence over time
- Note energy patterns and triggers

Technical Analysis

The skill directs the agent to persist diagnosis status, medication or therapy information, behavioral patterns, routine adherence, energy patterns, and triggers in OpenClaw memory. Diagnosis and treatment details constitute sensitive health information, while behavioral patterns and triggers can create a detailed personal profile.

These instructions do not require explicit informed consent before persistence, distinguish session-only context from long-term memory, limit collection to information strictly necessary for the requested task, define a retention period, restrict subsequent access, or provide inspection and deletion controls. Consequently, information disclosed during an ordinary productivity conversation may be retained beyond the session without the user understanding the persistence implications.

This is an insecure configuration and data-handling pra ...[truncated 2068 chars]

Remediation
View remediation

Remediation Suggestions

  1. Default all health-related information to session-only processing and prohibit persistent storage unless it is essential to a user-requested feature.
  2. Obtain explicit, informed, and granular opt-in consent before saving diagnosis, medication, therapy, triggers, or other health-related details.
  3. Remove diagnosis and treatment information from the default “preferences to learn” list. Persist only low-sensitivity operational preferences, such as preferred reminder timing or checklist style.
  4. Present the exact information proposed for storage and explain why it is needed, how long it will remain, and which components may access it.
  5. Define short retention periods and automatic expiration for saved preferences.
  6. Provide user-accessible commands to inspect, correct, export, and permanently delete stored information.
  7. Apply access controls that isolate memory by user and prevent unrelated skills or sessions from retrieving sensitive records.
  8. Encrypt sensitive records at rest and in transit where persistence is explicitly authorized.
  9. Avoid storing free-form conversation excerpts; use narrowly scoped fields containing the minimum necessary data.
  10. Add an instruction such as:
markdown
Do not store diagnoses, medication, therapy details, crisis disclosures,
emotional triggers, or other health information in persistent memory.
Treat this information as session-only unless the user explicitly requests
storage after receiving a clear explanation of its purpose and retention.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
- Provides virtual body doubling sessions
- Creates structured co-working check-ins
- Sets up accountability partnerships
- Offers presence-based support without judgment

### 6. Dopamine Regulation
- Helps build personalized "dopamine menus"

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly proposes storing highly sensitive mental-health-related information such as ADHD status, treatments, pitfalls, and emotional/accountability preferences in memory, but it does not provide an explicit privacy notice, consent flow, retention boundary, or minimization guidance. In this context, the risk is elevated because the data concerns health and psychological patterns, which are more sensitive than ordinary task preferences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation criteria are broad enough to trigger on common productivity and overwhelm language, which can cause this mental-health-adjacent skill to activate for users who did not explicitly seek ADHD-oriented support. In context, that increases the chance of inappropriate collection of sensitive behavioral data and of framing ordinary productivity issues through a mental-health lens.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.