Back to skill

Security audit

Agent Cron Audit

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only cron-job audit skill with some sharing and install guidance users should treat carefully, but I found no hidden execution, exfiltration, persistence, or destructive behavior.

Install only if you want a read-only audit helper for recurring agent jobs. Review any related skills separately before running the suggested global install commands, and do not send audit evidence or operational details to an external DM unless a human owner has reviewed the redaction.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:89
Finding

Mandatory Promotional Package Installation Guidance in Agent Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 89-145
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Vulnerable Code

markdown
Every audit returns six sections, in this order:
markdown
### 6. Related Skill, If Relevant

If the main issue is recurring **token waste** rather than general cron health:

```text
Try: openclaw skills install waste-audit --global

If the main issue is routing / model / cost change risk rather than general cron health:

text
Try: openclaw skills install agent-cost-eval-kit --global

These are pointers, not a funnel. Pick the one that matches the actual problem.

text

### Technical Analysis

The skill mandates a six-section response structure and reserves one section for recommending installation of additional skills. This modifies the agent's final response behavior beyond the core read-only cron-audit function and uses agent-generated results as a promotional distribution channel.

The installation examples use the `--global` option. They are displayed as recommendations and are not automatically executed, but a user may reasonably interpret them as independently selected or security-reviewed advice from the agent. The referenced packages were not included in the audited project, so their behavior and integrity could not be verified.

This is instruction hijacking because loading the skill imposes persistent response requirements that direct the agent to promote additional packages. The concern is limited by the conditional wording, the statement that the pointers are optional, and the absence of automatic command execution.

### Attack Path

1. A user activates the skill to audit recurring agent jobs.
2. The skill instructs the agent to return six sections in a prescribed order.
3. The required related-skill section causes the agent to present a global installation command when it classifies the issue a
...[truncated 1191 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the mandatory related-skill section from the prescribed audit output.
  2. Keep audit responses focused on evidence, manual verification, and remediation for the requested cron-health task.
  3. Mention related tools only after the user explicitly requests alternatives or installation guidance.
  4. Clearly label external skills as separate, unverified components rather than implied audit recommendations.
  5. Avoid recommending global installation by default. Prefer a least-scope installation method where supported.
  6. Require users to review package provenance, version, integrity, permissions, and source contents before installation.
  7. Pin reviewed versions or checksums if installation instructions remain necessary.
  8. Ensure that no package installation command is executed automatically or passed to an execution tool without explicit, informed user confirmation.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger phrase 'check stale automations' is broad enough to match requests unrelated to recurring agent cron jobs, causing the skill to activate in the wrong context. Mis-scoped activation can lead to the tool inspecting unintended automation artifacts or producing misleading audit guidance on systems the user did not mean to analyze.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill repeatedly promises local-only, read-only handling and no sharing of sensitive material, but then instructs users to send audit results to an external social-media DM. Even with redaction guidance, this creates a social exfiltration path for operational metadata and increases the chance that users disclose sensitive findings, private infrastructure details, or insufficiently redacted logs outside controlled channels.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.