T06 · System Persistence
- Location
SKILL.md:26- Finding
Persistent Daily Update Task Executes Across Sessions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is transparent about being an auto-updater, but it creates a persistent daily job that can change Clawdbot and every installed skill without reviewing each update first.
Install only if you deliberately want unattended daily updates for Clawdbot and every installed skill. Prefer a check-only or approval-based workflow, pin or allowlist trusted components where possible, and make sure you know how to remove the cron job before enabling it.
SKILL.md:26Persistent Daily Update Task Executes Across Sessions
SKILL.md:48Unpinned Automatic Updates Trust Mutable Third-Party Releases
references/agent-guide.md:51Critical Update and Migration Failures Are Suppressed
The skill performs self-modification by running clawdhub update --all, which updates all installed skills automatically and unattended. This is dangerous because it allows code and behavior changes to be introduced into the agent environment on a schedule, increasing the blast radius of any compromised dependency, malicious skill update, or accidental breaking change.
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")
# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"
The description emphasizes convenience but does not prominently warn that enabling the skill will automatically and repeatedly modify installed software. Because it updates both the core bot and all skills on a schedule, users may consent without understanding the persistence, scope, and supply-chain risk of unattended updates.
The trigger phrase is broad enough that a user could invoke recurring automatic updates with a natural-language request that does not clearly convey the full consequence: scheduled software modification of the bot and all installed skills. In this context, the action creates persistence via cron and changes software state over time, so ambiguous activation increases the risk of unintended enablement.
The guide instructs the agent to configure unattended daily updates that modify the local installation and installed skills without any explicit user confirmation, rollback plan, or trust-policy constraints. Automatically applying package and skill updates expands supply-chain risk and can cause availability or integrity issues if a malicious, compromised, or simply broken update is published.
The guide persists an executable helper script under ~/.clawdbot/scripts/auto-update.sh and pairs it with a cron-based recurring task, creating durable behavior that continues to run after initial setup. Persistent update automation increases the risk of long-lived unintended changes, repeated execution of unsafe commands, and abuse if the script or its update path is later tampered with.
bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"
## Step 2: Create the Update Script (Optional)
For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:
No suspicious patterns detected.