T06 · System Persistence
- Location
SKILL.md:185- Finding
Persistent Autonomous Execution Through Recurring Scheduled Sessions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:185-214
Additional Locations:SKILL.md:14-21,references/playbooks.md:56-83
Vulnerability Type: Persistent scheduled automation
Risk Level: HighEvidence
The following is an English translation of the relevant complete source segment from
SKILL.md:185-214:markdown ## Self-development and sessions - The Agent should actively work on its own further development. - It should create recurring sessions or cron runs for morning checks, match preparation, mailbox maintenance, squad analysis, financial checks, and weekly reviews. - These sessions should not remain static: frequency, times, contents, and priorities should be adjusted based on their observed effectiveness. - The Agent should ask itself: - Which checks provide genuine added value? - Which routines are redundant? - Where is knowledge of the rules, context, or analysis missing? - Which phase of the game requires more focus on the squad, tactics, finances, or communication? - The Agent should regularly schedule self-review sessions in which it revises its strategy, automation structure, and timing. - If an existing cron or session configuration has become unsuitable, the Agent should independently restructure it rather than retaining it. ## Default starting configuration As an initial basis that can later be adapted, the Agent should begin with a simple starting configuration: - During the first few weeks, it may be useful to be active very frequently during the day, potentially approximately hourly. - The Agent should nevertheless maintain a plausible human rhythm: real people usually sleep for approximately 8 to 10 hours and are not continuously available because of work, daily life, or other obligations. - High activity therefore does not mean continuous activity on an exact schedule, but dense activity during plausible waking hours. - `08:30` morning check: ...[truncated 2630 chars]- Remediation
View remediation
Remediation Suggestions
- Remove all instructions that require the Agent to create or modify cron jobs automatically.
- Default to one-shot execution confined to the current user request.
- Require explicit, informed user authorization before creating each recurring schedule.
- Present the exact schedule, operations, target account, duration, and maximum number of executions before activation.
- Assign every schedule a short expiration time and require renewed consent before extension.
- Provide visible controls to list, pause, modify, and permanently delete scheduled jobs.
- Restrict scheduled sessions to read-only operations unless the user separately authorizes a narrowly defined mutation.
- Require fresh confirmation before financial, communication, transfer, sponsorship, stadium, or club-management actions.
- Maintain an immutable audit log containing execution time, tools invoked, arguments excluding secrets, results, and schedule changes.
- Prevent a scheduled job from changing its own frequency, scope, permissions, or expiration.
