T06 · System Persistence
- Location
INSTALL.md:63- Finding
Opt-In Installation Instructions Establish Persistent Scheduled Execution
- Content
View full analysis
/dev/null; echo "0 * * * * cd ~/.openclaw/workspace/skills/context-compactor && python3 integration.py --check") | crontab - # Delete old logs every day (crontab -l 2>/dev/null; echo "0 2 * * * cd ~/.openclaw/workspace/skills/context-compactor && find logs -name '*.log' -mtime +7 -delete") | crontab - ``` ``` ### Technical Analysis The installation guide tells users to modify their crontab. Once installed, the hourly entry survives the current Skill invocation and executes `integration.py` in future sessions. The second entry performs recurring deletion of matching log files. Scheduled monitoring is related to the declared automatic-compression functionality, but permanent scheduling is not necessary for manual context compression. The instructions do not make the persistence implications prominent, prevent duplicate entries, assign a unique marker to managed entries, or provide an uninstall procedure. There is also a functional safety concern: the audited `integration.py` does not implement the documented `--check` command-line interface in the examined source and ends with incomplete code. Consequently, the persistent task may repeatedly fail while still consuming resources and producing logs. ### Attack Path 1. A user follows the installation guide. 2. The shell pipeline copies the current crontab and appends the supplied entry. 3. The modified crontab is installed under the user's account. 4. Cron invokes code from the Skill directory every hour across future sessions. 5. Repeating the installation command creates duplicate entries, potentially causing multiple executions. 6. The daily cleanup task deletes matching logs older than seven days, reducing historical diagnostic evidence. ### ...[truncated 357 chars]- Remediation
View remediation
