Back to skill

Security audit

Feishu Cron Announce

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and mostly transparent, but it helps create persistent scheduled agent jobs that can repeatedly send generated results to Feishu without documenting enough limits or cleanup controls.

Install only if you intend to create recurring OpenClaw jobs that send their results to Feishu. Before using it, verify the Feishu open_id, review the exact prompt and schedule, avoid including secrets or private data in monitored output, and make sure you know how to list and delete the cron job afterward.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
SKILL.md:17
Finding

Persistent Cross-Session Agent Execution Through Scheduled Tasks

Content
View full analysis
" \ --cron "" \ --tz "Asia/Shanghai" \ --session isolated \ --message "<提示词:让 AI 检查什么并生成简短结论>" \ --announce \ --channel feishu \ --to "<飞书用户 open_id>" \ --best-effort-deliver ``` ### Technical Analysis The documented command uses `openclaw cron add` to register a recurring task that remains active after the current skill invocation and conversation end. Each scheduled occurrence starts an isolated agent session, processes the supplied `--message`, and sends the generated result to the Feishu identity specified by `--to`. Although scheduled Feishu announcements are the declared purpose of the skill, this mechanism creates cross-session persistence. The instructions do not require an explicit confirmation immediately before registration, constrain the scheduled prompt to approved operations, establish an expiration time, or document a command for disabling and deleting the task. The prompt, schedule, and recipient are represented as variable inputs. If untrusted content controls these values, a persistent task could repeatedly invoke available agent capabilities or deliver generated information to an unintended recipient. The exact capabilities available during execution depend on the permissions granted to the isolated scheduled session. ### Attack Path 1. A user or untrusted source supplies task parameters, including a cron schedule, agent prompt, or Feishu recipient. 2. The agent substitutes those values into the documented `openclaw cron add` command. 3. OpenClaw registers the task in its persistent scheduler. 4. The scheduler starts isolated agent sessions at the configured times without requiring renewed approval for every execution. 5. Each session processes the stored prompt and attempts to transmit its result to ...[truncated 1030 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs automatic delivery of task results to Feishu but does not warn users that monitored content may be transmitted to an external messaging destination. This creates a real risk of unintended disclosure of sensitive data, especially because the monitored output could include internal status, release details, or other confidential information and the recipient open_id is user-supplied.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill presents --tz Asia/Shanghai as a success-critical required parameter, and the template repeats that fixed locale setting as mandatory. This enforces a specific regional timezone without user opt-in or explanation that the skill is intended only for that locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.