T06 · System Persistence
- Location
README.md:113- Finding
Unnecessary Persistent Hourly Token-Refresh Job
- Content
View full analysis
/dev/null | grep -v outlook_refresh; echo "55 * * * * ${SKILL_DIR}/.venv/bin/python ${SKILL_DIR}/scripts/outlook_refresh.py >> ~/.openclaw/outlook_refresh.log 2>&1" ) | crontab - ``` **Vérification :** ```bash crontab -l | grep outlook_refresh ``` ``` ### Technical Analysis The installation instructions add an hourly cron entry that survives the current Skill invocation and user session. This persistence is not required for the declared Outlook-reading functionality because `ensure_valid_token()` already refreshes an expired token on demand whenever a Graph operation is performed. The scheduled command executes an interpreter and script from a mutable Skill directory. If either the virtual environment or `outlook_refresh.py` is subsequently replaced, the modified code will execute automatically every hour under the installing user's account. The installation pipeline also removes every existing crontab line containing the text `outlook_refresh`: ```bash grep -v outlook_refresh ``` This is not scoped to an entry uniquely owned by this Skill and can unintentionally delete unrelated scheduled jobs. ### Attack Path 1. A user follows the documented installation instructions. 2. An hourly cron entry is added to the user's crontab. 3. The Skill directory, refresh script, or virtual-environment interpreter is later modified through a compromised update, another local process, or writable directory permissions. 4. Cron executes the modified component every hour without furthe ...[truncated 662 chars]- Remediation
View remediation
