Back to skill

Security audit

Opencron Skill Repo

Security checks for vulnerabilities and agentic risk

Overview

This cron dashboard has a plausible purpose, but it exposes cron data and gateway tokens too broadly and relies on mutable remote code plus unmanaged background sync.

Review before installing. Treat the dashboard data as sensitive cron metadata. Do not use this as-is on a shared or networked host; first remove tokenized URLs and automatic after-run output, bind locally or add real authentication, remove wildcard CORS, pin or bundle the dashboard HTML, redact job prompts/secrets, and replace nohup sync with a managed process that has clear start, status, and stop controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:108
Finding

Mandatory Dashboard-Link Injection into Unrelated Agent Responses

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
update_canvas.py:18
Finding

Unpinned Remote HTML Is Downloaded and Deployed as Active Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
serve.py:20
Finding

Development Server Exposes Full Cron Definitions Without Authentication

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:50
Finding

Gateway Credential Is Embedded in a Public Plaintext HTTP URL

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
watch_sync.sh:1
Finding

Detached Infinite Sync Process Continuously Publishes Complete Job Data

Content
View full analysis
/dev/null sleep 30 done ``` The Skill directs users to detach it: ```markdown ### 2. Start the background sync ```bash nohup sh skills/opencron/watch_sync.sh & ``` Keeps `cron-data.json` in sync with `jobs.json` every 30 seconds. ``` ### Technical Analysis The script creates an indefinite process and the documented `nohup ... &` invocation causes it to continue after the initiating terminal session ends. It repeatedly copies the entire job database into a web-content directory without redaction, access validation, explicit file permissions, PID management, locking, or a documented stop mechanism. The dashboard needs selected display fields, not necessarily a continuous byte-for-byte publication of the full source file. Copying all fields violates data minimization and magnifies any canvas-server access-control failure. The process is persistent across shell sessions, although the supplied code does not install a reboot-surviving startup service. ### Attack Path 1. A user follows the instructions and starts the script using `nohup`. 2. The process remains active after the shell terminates. 3. Every 30 seconds, current `jobs.json` content is copied to `~/.openclaw/canvas/cron-data.json`. 4. Sensitive additions to cron definitions are automatically republished. 5. An attacker who can access the canvas directory through a server or misconfiguration retrieves the current data. 6. Because there is no managed lifecycle, users may remain unaware that publication continues. ### Imp ...[truncated 394 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
generate.py:21
Finding

Cron Data Can Break Out of the Generated Script Element

Content
View full analysis
window.__CRON_DATA__ = {json.dumps(data)};" html = html.replace("", f"{inject}\n") return html ``` ### Technical Analysis `json.dumps()` creates valid JavaScript-compatible JSON but does not make the result safe for direct insertion into an HTML `` sequence inside a JavaScript string as the end of the element. If any job-controlled string contains a payload such as: ```text ``` the browser closes the intended script element and parses the injected markup as executable code. This is a stored cross-site scripting condition because the payload is retained in `jobs.json` and becomes part of the generated standalone dashboard. The repository does not include the referenced `cron_dashboard.html`, so the generator cannot complete in the supplied snapshot. Nevertheless, the unsafe embedding operation is directly present and becomes exploitable whenever the expected template is supplied. ### Attack Path 1. An attacker causes a malicious string containing `` and a new script element to be stored in a cron-job field. 2. A user runs `generate.py` with the expected template available. 3. The malicious string is serialized by `json.dumps()` but remains capable of terminating the HTML script element. 4. The generated dashboard is opened in a browser. 5. The browser executes the injected script in the dashboard's origin. 6. The payload reads embedded job data o ...[truncated 455 chars]
Remediation
View remediation
` and parse its text safely. - Before HTML embedding, escape at least `<`, `>`, and `&` as Unicode escapes; also handle U+2028 and U+2029 for compatibility. - A safe serialization pattern should convert `<` to `\u003c`, preventing `` from appearing in the HTML source. - Treat every cron field as untrusted input, even if it normally originates from a local configuration file. - Add regression tests using mixed-case closing tags and payloads in every displayed string field. - Apply a restrictive CSP that disallows inline scripts after refactoring the page. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (34)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README instructs opening a URL with token=${OPENCLAW_GATEWAY_TOKEN} in the query string, exposing a sensitive token in browser history, logs, screenshots, referrers, and proxy/access logs. Because this skill is for an externally accessible dashboard, the context makes token leakage more dangerous: compromise of the token could grant unauthorized access to cron status or related protected resources.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is ներկայացված as a visual dashboard, but the instructions indicate installer/updater behavior including fetching remote content from GitHub, writing local files, and running background sync logic. This mismatch increases supply-chain and operator-trust risk because users may authorize it as a passive UI skill while it performs active code/data deployment tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation instructs constructing and exposing a URL containing the gateway token in the query string. Tokens in URLs are commonly leaked via logs, browser history, referrers, screenshots, and shared terminal output, granting unauthorized dashboard access if captured.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly require revealing a live access URL containing the gateway token to the user after every cron job run. This is direct secret disclosure, and anyone with access to the output can reuse the token to access the dashboard and potentially associated run data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Requiring the tokenized dashboard link to be printed after every cron run greatly increases the chance the token will be stored in logs, notifications, transcripts, or monitoring systems. Repetition magnifies exposure and turns a single secret into a routinely broadcast credential.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The installation block tells users to run a nohup background sync process during setup, which establishes persistence outside the user's current session. While not inherently malicious, instructing unattended persistence without prominent disclosure or controls is risky because it can keep running indefinitely and perform ongoing file or network activity.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

text
Clone https://github.com/firstfloris/opencron-skill into skills/opencron.
Run python3 skills/opencron/update_canvas.py to deploy the dashboard.
Run nohup sh skills/opencron/watch_sync.sh & to start background sync.
After every cron job run, show the user: "See cron status on OpenCron: <dashboard-url>"

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly says update_canvas.py fetches the latest dashboard from GitHub and writes local data, but provides no integrity checks, pinning, or warning about trusting remote content. This creates a supply-chain and local file modification risk: if the upstream content is compromised or unexpectedly changed, users may pull and deploy unsafe HTML or scripts into their environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The manual setup section repeats the nohup sh skills/opencron/watch_sync.sh & instruction, again creating session-independent persistence. In the context of a dashboard sync loop, this is more than cosmetic: it enables continual background execution that users may not monitor, increasing exposure if the script misbehaves or is later altered.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

2. Start sync

bash
nohup sh skills/opencron/watch_sync.sh &

3. Open

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to launch watch_sync.sh with nohup ... &, creating a persistent background process without clearly disclosing persistence, lifecycle, resource use, or stop instructions. Persistent unattended processes expand attack surface and can continue syncing or modifying state after the user forgets they were started.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documentation describes behaviors that require file read/write and network access, but it does not declare any tool scope or permissions boundary. This weakens reviewability and least-privilege controls, making it easier for a skill to perform broader actions than an operator expects.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

The documented use of nohup launches a persistent background process that continues independently of the initiating session. Persistence is not inherently malicious here, but it can create unmanaged long-running behavior, surprise operators, and complicate containment or auditing if the sync loop is compromised or misconfigured.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

2. Start the background sync

bash
nohup sh skills/opencron/watch_sync.sh &

Keeps cron-data.json in sync with jobs.json every 30 seconds.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation tells the operator to query an external IP-discovery service, which causes outbound network traffic unrelated to core dashboard rendering. This leaks infrastructure metadata to a third party and normalizes unnecessary external calls in routine usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The instructions direct use of an external IP-discovery service without warning that this reveals server metadata and performs third-party network access. Lack of disclosure can surprise operators and violate privacy or network policy expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill mandates contacting ifconfig.me after every cron job execution, creating repeated external beacons and unnecessary disclosure of server metadata. Because this occurs automatically and broadly, it increases privacy and operational risk beyond an initial setup step.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction to act after every cron job run is overly broad and can affect unrelated jobs and outputs. Broad trigger conditions increase the chance of accidental data exposure, noisy behavior, and unsafe automation across contexts where a dashboard link is not appropriate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs a recursive, forced deletion of the repository's .git directory immediately after cloning. Although the script logs cloning and deployment steps, it does not disclose that it will irreversibly remove version-control metadata, and there is no confirmation prompt or comment warning about that destructive action.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a dashboard for OpenClaw with live countdown timers, run history, and calendar view, implying real OpenClaw cron data. In this file, all job data and run history are fabricated in in-memory mock structures and the code explicitly labels the logic as using mock data, so the implemented behavior is a demo rather than a live dashboard.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The comment says the app logic is 'identical to production, but with mock data,' which suggests production-equivalent behavior aside from the data source. In practice, this file never connects to any real backend and all visible functionality depends on synthetic datasets, so the documentation overstates what the code actually demonstrates.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script reads cron job data from a sensitive per-user file in the home directory and embeds it directly into a standalone HTML artifact. Even though this is the advertised functionality, the generated file can expose job names, schedules, commands, paths, and error details to anyone who gains access to the HTML, and the code provides no warning, consent prompt, redaction, or access-control safeguard.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The server binds to 0.0.0.0, making the dashboard reachable from other hosts on the network, and the /cron-data endpoint explicitly allows any web origin to read its response via Access-Control-Allow-Origin: *. That exposes local cron metadata beyond the apparent 'local visual dashboard' use case and can let any website visited by the user harvest job names, schedules, and errors if the port is reachable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.