T06 · System Persistence
- Location
templates/crontab_example.txt:9- Finding
Persistent Scheduled Execution of Mutable Skill Scripts
- Content
View full analysis
> $WORKSPACE/logs/healthcheck_l2.log 2>&1 # L3 daily audit # Run every day at 08:00 0 8 * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/l3_daily_audit.py >> $WORKSPACE/logs/healthcheck_l3.log 2>&1 # Heartbeat check # Run every 30 minutes */30 * * * * cd $HEALTHCHECK_DIR && $PYTHON scripts/heartbeat.py >> $WORKSPACE/logs/heartbeat.log 2>&1 ``` `INSTALL.md:134-142`: ```bash # Linux sudo systemctl start cron sudo systemctl enable cron # macOS sudo launchctl load -w /System/Library/LaunchDaemons/com.vix.cron.plist ``` `SKILL.md:65-70`: ```bash ### 3. Setup Crontab ```bash cat templates/crontab_example.txt # Copy and edit crontab crontab -e ``` ``` ### Technical Analysis The project explicitly directs users to register three recurring cron jobs. These jobs survive the installation session and execute scripts from the user-writable Skill directory every 30 minutes, hourly, and daily. Scheduled execution is relevant to the declared continuous health-monitoring functionality and is presented transparently rather than installed silently. Nevertheless, it creates a persistent execution path. If the Skill directory is later modified through a compromised update, another process running as the user, or an untrusted replacement of the scripts, cron will execute the modified code automatically. The installation gui ...[truncated 2136 chars]- Remediation
View remediation
