Back to skill

Security audit

Cron Tool

Security checks for vulnerabilities and agentic risk

Overview

This cron-management skill is purpose-aligned, but it can persistently change or erase scheduled jobs with weak disclosure and a verified unsafe removal path.

Review carefully before installing. Use only if you specifically need a cron-editing CLI, back up your crontab first, avoid running it as a privileged or service account, and do not allow automated agent use of remove, enable, disable, or edit until the removal bug and confirmation gaps are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cron.py:85
Finding

Removing One Cron Entry Can Erase Unrelated Crontab Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill exposes command-line functionality but does not declare any explicit tool scope such as allowed-tools or permissions. In practice, a CLI-oriented skill can imply shell execution and file/environment access, so the absence of restrictions creates unnecessary ambiguity and may allow broader agent capabilities than intended.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/cron.py (reported line 16)May include surrounding context.

python
def get_crontab() -> str:
    """Get current crontab content."""
    try:
        result = subprocess.run(
            ["crontab", "-l"], capture_output=True, text=True, check=True
        )
        return result.stdout

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/cron.py (reported line 30)May include surrounding context.

python
"""Write content to crontab."""
    try:
        # Use stdin to avoid temp file issues
        proc = subprocess.Popen(
            ["crontab", "-"], 
            stdin=subprocess.PIPE, 
            stdout=subprocess.PIPE,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The remove operation deletes matching cron entries and immediately writes the modified crontab back via write_crontab(), but there is no confirmation prompt or explicit warning that this is a destructive change. Unlike restore_crons(), this path gives the user no chance to review or cancel an irreversible scheduling change.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Both enable_cron() and disable_cron() change active scheduled tasks and persist the modified crontab through write_crontab(), but neither function includes a confirmation prompt or explicit safety warning. These operations affect system task execution state and should disclose that impact before applying changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

edit_crontab() opens the current crontab in an editor and then unconditionally writes back whatever content is present after the editor closes. There is no review step, confirmation prompt, or user-facing warning that exiting the editor will replace the live crontab.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

The tool executes the program specified by the EDITOR environment variable without validation. If this script is launched in a context where environment variables can be influenced by an untrusted party, an attacker can cause arbitrary program execution under the current user's privileges.

Content

Scanner excerpt · scripts/cron.py (reported line 233)May include surrounding context.

python
try:
        # Open in editor
        editor = os.environ.get('EDITOR', 'vim')
        subprocess.call([editor, temp_file])
        
        # Read back
        with open(temp_file, 'r') as f:

Tainted flow: 'editor' from os.environ.get (line 232, credential/environment) → subprocess.call (code execution)

Medium
Category
Data Flow
Confidence
94% confidence
Finding

This is a true tainted-data-to-execution issue: untrusted data from the EDITOR environment variable flows directly into subprocess.call. In normal interactive use this may be acceptable, but in agent or automation contexts where the environment may be inherited or attacker-influenced, it becomes a straightforward arbitrary-code-execution vector.

Content

Scanner excerpt · scripts/cron.py (reported line 233)May include surrounding context.

python
try:
        # Open in editor
        editor = os.environ.get('EDITOR', 'vim')
        subprocess.call([editor, temp_file])
        
        # Read back
        with open(temp_file, 'r') as f:

Static analysis

No suspicious patterns detected.