T06 · System Persistence
- Location
SKILL.md:17- Finding
Persistent Cross-Session Agent Execution Through Scheduled Tasks
- Content
View full analysis
" \ --cron "" \ --tz "Asia/Shanghai" \ --session isolated \ --message "<提示词:让 AI 检查什么并生成简短结论>" \ --announce \ --channel feishu \ --to "<飞书用户 open_id>" \ --best-effort-deliver ``` ### Technical Analysis The documented command uses `openclaw cron add` to register a recurring task that remains active after the current skill invocation and conversation end. Each scheduled occurrence starts an isolated agent session, processes the supplied `--message`, and sends the generated result to the Feishu identity specified by `--to`. Although scheduled Feishu announcements are the declared purpose of the skill, this mechanism creates cross-session persistence. The instructions do not require an explicit confirmation immediately before registration, constrain the scheduled prompt to approved operations, establish an expiration time, or document a command for disabling and deleting the task. The prompt, schedule, and recipient are represented as variable inputs. If untrusted content controls these values, a persistent task could repeatedly invoke available agent capabilities or deliver generated information to an unintended recipient. The exact capabilities available during execution depend on the permissions granted to the isolated scheduled session. ### Attack Path 1. A user or untrusted source supplies task parameters, including a cron schedule, agent prompt, or Feishu recipient. 2. The agent substitutes those values into the documented `openclaw cron add` command. 3. OpenClaw registers the task in its persistent scheduler. 4. The scheduler starts isolated agent sessions at the configured times without requiring renewed approval for every execution. 5. Each session processes the stored prompt and attempts to transmit its result to ...[truncated 1030 chars]- Remediation
View remediation
