T06 · System Persistence
- Location
SKILL.md:122- Finding
Persistent Scheduled Execution Through Cron
- Content
View full analysis
"Sync every morning at 9am" or "Sync every Monday at 8am" The agent will create a cron job that runs in isolated mode with incremental sync — no duplicates. ``` ### Technical Analysis The Skill instructs the agent to create an operating-system cron job in response to a scheduling request. A cron entry persists beyond the current Skill execution and repeatedly launches code under the user's account. Scheduled synchronization is related to the declared functionality, but the instructions do not define: - The precise command that will be installed. - Absolute and immutable interpreter, script, and configuration paths. - A restricted execution environment. - A user-confirmation step showing the final cron entry. - Ownership tracking or an uninstall procedure. - Protections against later modification of the script or executable. Consequently, modifications to the script, configuration, Python interpreter, or `bb-browser` dependency after installation can affect every subsequent scheduled execution without renewed approval. ### Attack Path 1. A user asks the agent to synchronize content on a schedule. 2. Following `SKILL.md`, the agent creates a cron entry. 3. The cron entry survives the current session and repeatedly invokes the synchronization workflow. 4. An attacker or compromised dependency later modifies the invoked script, configuration, interpreter, or `bb-browser` executable. 5. Cron automatically executes the modified component under the user's account at the next scheduled interval. ### Impact Assessment Successful exploitation provides recurring code execution with the permissions of the user who owns the cron job. This can include access to the user's files, Obsidian vault, process ...[truncated 210 chars]- Remediation
View remediation
