T06 · System Persistence
- Location
SKILL.md:123- Finding
Recurring Cron Jobs Create Cross-Session Persistence Without Defined Lifecycle Controls
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 123-134
Vulnerability Type: Persistent scheduled task creation
Risk Level: MediumVulnerable Code
markdown ## Automation ### Cron Jobs Set up two cron jobs: 1. **Job Finder** — Daily at user's preferred time (default 9 AM local): - Query all APIs, parse new JDs, update tracker - `sessionTarget: "isolated"`, `delivery: "announce"` 2. **Status Update** — Daily at user's preferred time (default 11 AM local): - Read tracker, compile summary, send to user's messaging channel - `sessionTarget: "isolated"`, `delivery: "announce"`Technical Analysis
The Skill directs the agent to create two recurring cron jobs. These scheduled jobs survive the original interactive run and repeatedly initiate isolated sessions that read local job-tracking information, contact external job APIs, update stored records, and deliver information through a messaging channel.
Scheduled automation is part of the declared job-search functionality, and the audited text does not establish that it is intended as a covert backdoor. However, the instructions do not require explicit confirmation immediately before creating the jobs, define an expiration time, or provide procedures to enumerate, pause, or remove existing schedules. Consequently, a user may unintentionally authorize persistent processing after expecting the original session to end.
Attack Path
- A user activates the Skill to configure job-search automation.
- The agent follows the instruction to create the Job Finder and Status Update cron jobs.
- The scheduled entries persist beyond the initiating session.
- At their configured times, isolated sessions read local configuration and job-tracking data.
- The sessions contact configured external job services and send summaries through the user's messaging channel.
- This activity continues indefinitely unless the underlying s ...[truncated 726 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed user confirmation immediately before creating each scheduled task.
- Display the exact schedule, task purpose, files accessed, external services contacted, and messaging destination before confirmation.
- Default to one-time execution unless recurring automation is specifically requested.
- Assign a finite expiration date or maximum run count to every schedule by default.
- Provide documented commands to list, pause, resume, and permanently delete all schedules created by the Skill.
- Prevent duplicate schedules by checking for an existing task before creating another one.
- Apply least privilege to isolated sessions, limiting them to the required project files, API hosts, and messaging destination.
- Record task creation, execution, failure, and deletion in an auditable local log without exposing credentials or unnecessary personal data.
