T06 · System Persistence
- Location
SKILL.md:215- Finding
Persistent Daily Execution Through Cron and a macOS LaunchAgent
- Content
View full analysis
> /path/to/logs/email_summary.log 2>&1 ``` ```xml Label com.email.dailysummary ProgramArguments /bin/bash /path/to/email_daily_summary.sh StartCalendarInterval Hour 9 Minute 0 StandardOutPath /tmp/email_summary.log StandardErrorPath /tmp/email_summary_error.log ``` ```bash launchctl load ~/Library/LaunchAgents/com.email.dailysummary.plist ``` ### Technical Analysis The Skill instructs users to register a cron entry or load a macOS LaunchAgent that invokes a shell script every day. Both mechanisms survive the original Skill invocation and continue executing until explicitly removed. Scheduled execution is consistent with the optional daily-automation feature, but it is not required for the core function of producing an email summary on demand. It therefore exceeds the minimum privileges and lifecycle needed for the basic task. The documentation does not provide an uninstall procedure, verify the integrity or ownership of the referenced script, enforce restrictive file permissions, or require an explicit security confirmation before enabling persistence. Because the scheduler invokes a mutable filesystem path through `/bin/bash`, any party able to replace or modify that script can convert the legi ...[truncated 1192 chars]- Remediation
View remediation
