T06 · System Persistence
- Location
README.md:299- Finding
Persistent Autonomous Execution Through Scheduled OpenClaw Jobs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill openly teaches agents to run recurring autonomous work from mutable task queues, which is useful for its purpose but needs careful review before enabling.
Install only if you intentionally want agents to work without prompts. Before enabling cron or frequent heartbeat runs, restrict what tasks may be picked up, who can edit the queue, what files and external channels the agent can access, and when approval is required for writes, messages, spending, command execution, or spawning agents. Also document how to list and disable every scheduled job.
README.md:299Persistent Autonomous Execution Through Scheduled OpenClaw Jobs
The README explicitly encourages agents to 'stop waiting for prompts' and to work continuously between human messages, but it does not pair that autonomy with safety boundaries, approval gates, or warnings about unattended actions. In an agent skill, this can lead to unintended actions, excessive spending, data access, or modification of files/systems without timely human oversight.
The documented cron jobs schedule autonomous work sessions and reporting that run without a human prompt, including directives to review queues, pick priorities, and perform research or analysis. Because these examples normalize unattended execution without warning about scope, permissions, or side effects, they increase the chance of unreviewed actions and persistent background behavior.
The description "Stop waiting for prompts. Keep working." is extremely broad and reads like a general activation or usage condition without any scope constraints. It does not specify when this skill should apply versus when it should not, increasing the risk of accidental or overly broad use.
The quick-start guidance explicitly instructs users to 'Set up cron jobs for overnight work and daily reports' and to 'Watch work happen without prompting,' which encourages persistent, trigger-light autonomous execution. In the context of an agent skill centered on proactive behavior and 'continuous operation,' this can lead to unauthorized actions, runaway task execution, or work being performed outside clear user intent and review boundaries.
The skill explicitly instructs the agent to autonomously read a queue, select tasks, perform work, and continue onto additional tasks whenever time remains. In an agent-autonomy skill, this broad standing directive can cause action outside a narrowly scoped user request, increasing the chance of unintended file changes, task execution, or persistence beyond the intended context.
The skill directs the agent to update task queues, log to memory files, and post team updates without warning the user that project records will be modified. In this context, the danger is not obviously malicious content but silent state mutation: the agent may alter coordination artifacts or create audit noise without explicit consent or review.
Multiple cron commands specify '--tz "America/Vancouver"', which imposes a locale-specific setting in natural-language usage guidance. Because the README does not explicitly offer timezone selection or clarify that users should substitute their own locale, this can violate the policy against forcing a specific locale without opt-in.
The trigger condition 'If nothing urgent' is underspecified and leaves the agent to self-interpret when it may enter work mode. That ambiguity can lead to premature autonomous action, especially in environments where urgency or priority is not formally defined.
No suspicious patterns detected.