Back to skill

Security audit

Temp Agent Autonomy Kit

Security checks for vulnerabilities and agentic risk

Overview

This skill openly teaches agents to run recurring autonomous work from mutable task queues, which is useful for its purpose but needs careful review before enabling.

Install only if you intentionally want agents to work without prompts. Before enabling cron or frequent heartbeat runs, restrict what tasks may be picked up, who can edit the queue, what files and external channels the agent can access, and when approval is required for writes, messages, spending, command execution, or spawning agents. Also document how to list and disable every scheduled job.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
README.md:299
Finding

Persistent Autonomous Execution Through Scheduled OpenClaw Jobs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly encourages agents to 'stop waiting for prompts' and to work continuously between human messages, but it does not pair that autonomy with safety boundaries, approval gates, or warnings about unattended actions. In an agent skill, this can lead to unintended actions, excessive spending, data access, or modification of files/systems without timely human oversight.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented cron jobs schedule autonomous work sessions and reporting that run without a human prompt, including directives to review queues, pick priorities, and perform research or analysis. Because these examples normalize unattended execution without warning about scope, permissions, or side effects, they increase the chance of unreviewed actions and persistent background behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description "Stop waiting for prompts. Keep working." is extremely broad and reads like a general activation or usage condition without any scope constraints. It does not specify when this skill should apply versus when it should not, increasing the risk of accidental or overly broad use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The quick-start guidance explicitly instructs users to 'Set up cron jobs for overnight work and daily reports' and to 'Watch work happen without prompting,' which encourages persistent, trigger-light autonomous execution. In the context of an agent skill centered on proactive behavior and 'continuous operation,' this can lead to unauthorized actions, runaway task execution, or work being performed outside clear user intent and review boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly instructs the agent to autonomously read a queue, select tasks, perform work, and continue onto additional tasks whenever time remains. In an agent-autonomy skill, this broad standing directive can cause action outside a narrowly scoped user request, increasing the chance of unintended file changes, task execution, or persistence beyond the intended context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs the agent to update task queues, log to memory files, and post team updates without warning the user that project records will be modified. In this context, the danger is not obviously malicious content but silent state mutation: the agent may alter coordination artifacts or create audit noise without explicit consent or review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Multiple cron commands specify '--tz "America/Vancouver"', which imposes a locale-specific setting in natural-language usage guidance. Because the README does not explicitly offer timezone selection or clarify that users should substitute their own locale, this can violate the policy against forcing a specific locale without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger condition 'If nothing urgent' is underspecified and leaves the agent to self-interpret when it may enter work mode. That ambiguity can lead to premature autonomous action, especially in environments where urgency or priority is not formally defined.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.