T06 · System Persistence
- Location
SKILL.md:12- Finding
Persistent Autonomous Execution Through Recurring Cron Jobs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill openly creates recurring project automation, but it can keep running scripts and changing files on the main session without clear limits, approval, or cleanup instructions.
Install only if you intentionally want unattended recurring automation for this specific crypto backtest project. Before enabling it, confirm the schedules, working directory, permitted actions, expiration or run limit, and exact commands to disable or remove all cron jobs.
SKILL.md:12Persistent Autonomous Execution Through Recurring Cron Jobs
The skill explicitly instructs the agent to set up cron-driven automation that performs real actions such as running scripts, modifying code, and producing files, but it does not require clear user consent at execution time or warn that ongoing background changes will continue after setup. In an agent context, this can lead to persistent unattended system modifications, noisy or unintended resource usage, and surprise changes to project state beyond the user’s immediate expectation.
The daily report schedule specifies a fixed timezone, which imposes a locale-specific behavior in the skill instructions. The file does not indicate that this timezone is optional, user-selected, or required for a documented region-specific purpose.
No suspicious patterns detected.