T06 · System Persistence
- Location
SKILL.md:44- Finding
Persistent Unattended Execution Through an Automatic Cron Task
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 4 and 44-48; lines 99-100
Vulnerability Type:T06: System Persistence
Risk Level: HighVulnerable Code
text - **Trigger Timing**: Auto-run every minute after Agent startup; also supports manual trigger via `/binance-fetch-data`; runs 24/7, aligned with Binance 7×24 trading hourstext ### 3.4 Running Rule - Auto-start cron task at Agent startup - Run at second 0 of every minute - Auto-cache data after fetch - Sync to all related Skills for calltext ## Auto-Run Trigger 24/7, run every minute automatically after activationTechnical Analysis
The Skill explicitly instructs the Agent to create or activate a cron-style task that runs every minute, 24 hours a day. This changes the behavior from a user-invoked data-fetch operation into persistent, unattended execution tied to Agent startup.
The scheduled task continuously performs external network requests, writes cached state, and synchronizes that state with related Skills. No explicit consent workflow, scheduler scope, ownership model, disable mechanism, resource limit, or uninstall procedure is defined.
Although the repository contains only instruction files and does not include the scheduler implementation, an Agent that follows these instructions would establish the persistent behavior described by the Skill.
Attack Path
- A user installs and activates the data-fetcher Skill.
- The Agent interprets the running rules and registers or enables the requested cron task.
- The task begins at Agent startup and executes at second zero of every minute.
- Each invocation performs Binance network requests, updates cached data, and synchronizes data to related Skills.
- The behavior continues without a new user request and may persist across individual Skill invocations or Agent sessions, depending on the scheduler used.
- If the Skill or one of its ...[truncated 853 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic scheduler registration from the default activation path.
- Require explicit, informed user consent before creating any scheduled task.
- Display the exact scheduler entry, command, frequency, working directory, network destinations, and execution identity before installation.
- Prefer a foreground or user-invoked operation unless continuous execution is essential.
- If scheduling is required, use a least-privileged service account and restrict filesystem and network access.
- Add execution locking, rate limits, timeouts, bounded retries, and resource quotas.
- Provide documented commands to pause, disable, inspect, and permanently remove the scheduled task.
- Ensure uninstalling the Skill also removes all scheduler entries and cached state.
- Pin and verify every component executed by the scheduled task so that reviewed behavior cannot change silently.
