T06 · System Persistence
- Location
SKILL.md:52- Finding
Persistent Autonomous Execution Through a Recurring Cron Job
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 52-56
Vulnerability Type:T06: System Persistence
Risk Level: HighVulnerable Code:
markdown ## Cron Integration This project uses Gateway cron (not heartbeat) for autonomous loops. After installing this skill, ensure: - Overwrite the workspace root `CRON_PROMPT.md` with `skills/openclaw-minecraft/CRON_PROMPT.md` (always, regardless of existing file). - A cron job runs every 30 seconds and instructs the agent to follow `CRON_PROMPT.md`.Technical Analysis
The skill directs the installer to create a scheduled task that invokes the agent every 30 seconds. This task persists beyond the run in which the skill was installed and repeatedly causes authenticated network requests and autonomous Minecraft actions.
The instructions provide no execution lifetime, automatic expiration, resource limit, teardown procedure, or requirement for explicit operator confirmation. Consequently, installing the skill can establish an indefinite cross-session automation mechanism.
The scheduled task follows
CRON_PROMPT.md, which requires the agent to load credentials, query the external controller, plan an action bundle, submit the bundle, and record decisions on each eligible cycle.Attack Path
- A user or agent installs the skill and follows its installation instructions.
- The installation process creates a cron job that runs every 30 seconds.
- Each scheduled invocation directs the agent to follow the workspace
CRON_PROMPT.md. - The cron prompt loads the stored bearer token and bot identifier.
- The agent sends authenticated state and action requests to the configured external controller.
- This behavior continues across sessions until the cron job is manually identified and removed.
Impact Assessment
The mechanism obtains persistent ability to trigger agent activity within the cron job's execution context. It can repeated ...[truncated 470 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not install or enable a cron job automatically as part of skill installation.
- Require explicit, informed operator approval before creating any scheduled task.
- Display the exact schedule, command or prompt target, credentials accessed, and expected actions before approval.
- Assign a bounded lifetime or maximum invocation count to the task.
- Use a substantially lower frequency unless a 30-second interval is operationally necessary.
- Scope the task to a dedicated workspace and least-privileged controller token.
- Provide documented commands to inspect, disable, and permanently remove the scheduled task.
- Add an emergency stop flag that is checked before credentials are loaded or network requests are made.
- Record creation and removal events in an operator-visible audit log.
