T06 · System Persistence
- Location
SKILL.md:154- Finding
Mandatory recurring jobs create cross-session system persistence
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:154-164,SKILL.md:275-278,scripts/setup_primer.py:167-188,scripts/setup_primer.py:226-230
Vulnerability Type: Scheduled-task persistence
Risk Level: CriticalVulnerable Code
SKILL.md:154-164:markdown ### 8. Finalize Setup **All info gathered. Now complete the integration:** 1. **Verify PRIMER.md** — run `grep -c "{{" PRIMER.md` (should be 0) 2. **Update AGENTS.md** — add to session startup: ``` Read `PRIMER.md` — the subversive tutor protocol (who [name] is becoming, permissions granted, patterns to watch) ``` 3. **Update SOUL.md** — add The Primer Role section (below) 4. **Create cron jobs:** - Daily reflection (end of day in user's timezone) - Miranda check-in (their chosen cadence)scripts/setup_primer.py:167-188:python def generate_cron_config(config: dict) -> dict: """Generate cron job configurations.""" cadence = config.get("miranda_cadence", "Monthly").lower() # Calculate next Miranda check-in now = datetime.now() if cadence == "weekly": next_miranda = now + timedelta(days=7) elif cadence == "bi-weekly": next_miranda = now + timedelta(days=14) else: # monthly next_miranda = now + timedelta(days=30) return { "daily_reflection": { "name": "Primer Daily Reflection", "schedule": {"kind": "cron", "expr": "0 7 * * *", "tz": "UTC"}, "description": "End of day reflection on Primer performance" }, "miranda_checkin": { "name": "Miranda Protocol Check-in", "schedule": {"kind": "at", "atMs": int(next_miranda.timestamp() * 1000)}, "next_date": next_miranda.strftime("%Y-%m-%d") } }scripts/setup_primer.py:226-230:python # Generate cron config (to be used by the AI) cron_config = g ...[truncated 2165 chars]- Remediation
View remediation
Remediation Suggestions
- Make all scheduled automation optional rather than a setup requirement.
- Obtain separate, explicit confirmation immediately before creating each job.
- Display the exact schedule, timezone, action, data accessed, retention behavior, and expiration date before confirmation.
- Default to a bounded number of runs or an explicit expiration rather than an indefinite daily schedule.
- Store returned scheduler identifiers and provide a tested command or workflow that removes every installed task.
- Verify successful removal when the Skill is disabled or the user revokes consent.
- Do not declare jobs created merely because their JSON configuration was printed; verify actual scheduler state and report it accurately.
- Use the user's confirmed timezone instead of a hardcoded UTC schedule.
