Back to skill

Security audit

Cron & Scheduling

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent cron and systemd scheduling guide, but it includes under-warned destructive and privileged examples plus unsafe shell patterns that should be reviewed before use.

Install only if you want a command-reference style scheduling skill and are comfortable reviewing commands before use. Pay special attention before allowing it to remove crontabs, schedule reboots, enable systemd timers, write under /var/log, or run examples as root; its wrapper and lock snippets should be hardened before production use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:349
Finding

Path Traversal Through Unvalidated Job Name in Logging Wrapper

Content
View full analysis
[args...]}" shift COMMAND=("$@") LOG_DIR="/var/log/cron-jobs" mkdir -p "$LOG_DIR" LOG_FILE="$LOG_DIR/$JOB_NAME.log" ``` ### Technical Analysis The wrapper accepts `JOB_NAME` from its first command-line argument and directly incorporates it into `LOG_FILE`. Although the variable is quoted during subsequent use, quoting only prevents shell word splitting and command substitution; it does not prevent filesystem path traversal. A job name containing directory separators or traversal components, such as `../../target`, can cause the resolved log path to escape `/var/log/cron-jobs`. The `.log` suffix limits the set of directly addressable names but does not prevent writes outside the intended directory. Existing symbolic links can further increase the reachable scope. This example is particularly sensitive because cron wrappers commonly run under service accounts or `root`, and the document places logs under `/var/log`, which usually requires elevated privileges. ### Attack Path 1. An attacker gains the ability to configure a scheduled invocation or otherwise control the wrapper's first argument. 2. The attacker supplies a crafted job name containing path traversal components, such as `../../some-directory/target`. 3. The wrapper constructs a path resembling: ```text /var/log/cron-jobs/../../some-directory/target.log ``` 4. The operating system resolves the traversal components outside the intended logging directory. 5. When the wrapper appends status messages or command output, data is written using the wrapper's privileges. 6. If the destination is an existing file or a usable symbolic link, the attacker may corrupt or modify a file accessible to the scheduled job. ### Impact Assessment ...[truncated 661 chars]
Remediation
View remediation
&2 exit 2 } ``` 2. Explicitly reject `/`, `\`, `..`, control characters, and empty values. 3. Canonicalize the resulting path and verify that it remains beneath the canonical `LOG_DIR`. 4. Create the log directory with restrictive ownership and permissions: ```bash install -d -m 0750 -o root -g cron-jobs /var/log/cron-jobs ``` 5. Prevent symbolic-link following when opening log files, using a small helper that supports `O_NOFOLLOW` where shell facilities are insufficient. 6. Run each scheduled task under the least-privileged dedicated service account rather than `root`. 7. Ensure only trusted administrators can configure the wrapper's arguments or modify the relevant crontab or timer unit. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:390
Finding

Predictable Lock File in World-Writable Temporary Directory Enables Symlink File Clobbering

Content
View full analysis
"$LOCKFILE" flock -n 200 || { echo "Already running"; exit 0; } ``` ### Technical Analysis The locking example uses a fixed, predictable path in `/tmp`, a directory normally writable by every local user. The redirection operator opens the path with write and truncation behavior before `flock` is applied. Standard shell redirection follows symbolic links. A local attacker can create `/tmp/myjob.lock` as a symbolic link to another file before the privileged scheduled process starts. When the process executes `exec 200>"$LOCKFILE"`, the symbolic-link target is opened and truncated with the privileges of the scheduled job. The lock is acquired only after this destructive open, so `flock` does not mitigate the attack. The fixed pathname also allows another user to pre-create the file with hostile ownership or permissions, potentially causing denial of service even when a useful symbolic-link target is unavailable. ### Attack Path 1. The attacker predicts the documented lock path `/tmp/myjob.lock`. 2. Before the scheduled task starts, the attacker creates a symbolic link: ```bash ln -s /path/to/privileged-writable-target /tmp/myjob.lock ``` 3. A privileged cron job or systemd service runs the documented locking code. 4. The shell processes `exec 200>"$LOCKFILE"` and follows the symbolic link. 5. The target file is opened with truncation using the scheduled process's privileges. 6. Only after the target has been truncated does the process attempt to acquire the lock. 7. The attacker repeats the operation when the predictable lock path becomes available or uses pre-creation to cause persistent task failures. ### Impact Assessment If the scheduled task runs as `root`, an unprivileged local user may cause truncation of ...[truncated 560 chars]
Remediation
View remediation
>"$LOCKFILE" flock -n 200 || { echo "Already running"; exit 0; } ``` 4. Note that append mode alone does not prevent symbolic-link following; the parent directory must be inaccessible to untrusted users. 5. Where available, use a lock-opening helper that applies `O_NOFOLLOW` and verifies that the opened object is a regular file owned by the expected account. 6. For systemd services, consider using service-manager controls to prevent overlapping executions instead of manually managing a lock in `/tmp`. 7. Run the scheduled process with the minimum filesystem permissions required for its task. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (14)

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

bash
# Edit current user's crontab
crontab -e

# List current crontab
crontab -l

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
crontab -e

# List current crontab
crontab -l

# Edit another user's crontab (root)
sudo crontab -u www-data -e

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
crontab -e

# List current crontab
crontab -l

# Edit another user's crontab (root)
sudo crontab -u www-data -e

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

md
crontab -e

# List current crontab
crontab -l

# Edit another user's crontab (root)
sudo crontab -u www-data -e

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
crontab -l

# Edit another user's crontab (root)
sudo crontab -u www-data -e

# Remove all cron jobs (be careful!)
crontab -r

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

md
crontab -l

# Edit another user's crontab (root)
sudo crontab -u www-data -e

# Remove all cron jobs (be careful!)
crontab -r

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown includes crontab -r, which removes all cron jobs, with only a brief parenthetical note saying 'be careful!'. This is a destructive operation affecting user task configuration, but the skill does not provide a stronger warning about irreversibility, recommend backup-first workflow in the same section, or advise explicit confirmation before use.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

bash
# Enable and start the timer
sudo systemctl daemon-reload
sudo systemctl enable --now backup.timer

# Check timer status

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

bash
# Enable and start the timer
sudo systemctl daemon-reload
sudo systemctl enable --now backup.timer

# Check timer status

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

bash
# Enable and start the timer
sudo systemctl daemon-reload
sudo systemctl enable --now backup.timer

# Check timer status

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

bash
# Enable and start the timer
sudo systemctl daemon-reload
sudo systemctl enable --now backup.timer

# Check timer status
systemctl list-timers

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The one-off scheduling examples include echo "reboot" | at now + 30 minutes, which can interrupt active sessions and affect system availability. The surrounding markdown does not explicitly warn users that this is disruptive and should only be used with prior notice and confirmation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

Run something after a delay

(sleep 3600 && /opt/scripts/task.sh) &

With nohup (survives logout)

nohup bash -c "sleep 7200 && /opt/scripts/task.sh" &

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

Run something after a delay

(sleep 3600 && /opt/scripts/task.sh) &

With nohup (survives logout)

nohup bash -c "sleep 7200 && /opt/scripts/task.sh" &

text

Static analysis

No suspicious patterns detected.