T09 · Insecure Skill Coding Practices
- Location
scripts/cron.py:85- Finding
Removing One Cron Entry Can Erase Unrelated Crontab Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This cron-management skill is purpose-aligned, but it can persistently change or erase scheduled jobs with weak disclosure and a verified unsafe removal path.
Review carefully before installing. Use only if you specifically need a cron-editing CLI, back up your crontab first, avoid running it as a privileged or service account, and do not allow automated agent use of remove, enable, disable, or edit until the removal bug and confirmation gaps are fixed.
scripts/cron.py:85Removing One Cron Entry Can Erase Unrelated Crontab Content
The skill exposes command-line functionality but does not declare any explicit tool scope such as allowed-tools or permissions. In practice, a CLI-oriented skill can imply shell execution and file/environment access, so the absence of restrictions creates unnecessary ambiguity and may allow broader agent capabilities than intended.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def get_crontab() -> str:
"""Get current crontab content."""
try:
result = subprocess.run(
["crontab", "-l"], capture_output=True, text=True, check=True
)
return result.stdout
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""Write content to crontab."""
try:
# Use stdin to avoid temp file issues
proc = subprocess.Popen(
["crontab", "-"],
stdin=subprocess.PIPE,
stdout=subprocess.PIPE,
The remove operation deletes matching cron entries and immediately writes the modified crontab back via write_crontab(), but there is no confirmation prompt or explicit warning that this is a destructive change. Unlike restore_crons(), this path gives the user no chance to review or cancel an irreversible scheduling change.
Both enable_cron() and disable_cron() change active scheduled tasks and persist the modified crontab through write_crontab(), but neither function includes a confirmation prompt or explicit safety warning. These operations affect system task execution state and should disclose that impact before applying changes.
edit_crontab() opens the current crontab in an editor and then unconditionally writes back whatever content is present after the editor closes. There is no review step, confirmation prompt, or user-facing warning that exiting the editor will replace the live crontab.
The tool executes the program specified by the EDITOR environment variable without validation. If this script is launched in a context where environment variables can be influenced by an untrusted party, an attacker can cause arbitrary program execution under the current user's privileges.
try:
# Open in editor
editor = os.environ.get('EDITOR', 'vim')
subprocess.call([editor, temp_file])
# Read back
with open(temp_file, 'r') as f:
This is a true tainted-data-to-execution issue: untrusted data from the EDITOR environment variable flows directly into subprocess.call. In normal interactive use this may be acceptable, but in agent or automation contexts where the environment may be inherited or attacker-influenced, it becomes a straightforward arbitrary-code-execution vector.
try:
# Open in editor
editor = os.environ.get('EDITOR', 'vim')
subprocess.call([editor, temp_file])
# Read back
with open(temp_file, 'r') as f:
No suspicious patterns detected.