Back to skill

Security audit

Cron Mastery

Security checks for vulnerabilities and agentic risk

Overview

The skill is a scheduling guide, but its reusable examples can forward reminders and email summaries to a fixed Telegram recipient and include unsafe global cron-state deletion advice.

Review this skill before installing. Replace all fixed Telegram IDs and example timezones with user-confirmed placeholders, require consent before scheduling email summaries or external delivery, and do not follow the state-file deletion advice unless you have a backup and a supported recovery procedure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/templates.md:60
Finding

Hardcoded Telegram Recipient Can Disclose Private Reminder and Email Content

Content
View full analysis

Vulnerability Details

File Location: references/templates.md:60-83; duplicated delivery pattern in SKILL.md:49-62
Vulnerability Type: Hardcoded external delivery destination
Risk Level: High

Vulnerable Code

json
{
  "action": "add",
  "job": {
    "name": "Morning Briefing",
    "schedule": {
      "kind": "cron",
      "expr": "0 8 * * *",
      "tz": "Africa/Cairo"
    },
    "payload": {
      "kind": "agentTurn",
      "message": "Good morning! Search for unread emails and top tech news, then summarize them."
    },
    "sessionTarget": "isolated",
    "wakeMode": "now",
    "delivery": {
      "mode": "announce",
      "channel": "telegram",
      "to": "1027899060"
    }
  }
}

The same fixed destination also appears in the primary reminder example:

json
{
  "name": "Remind: Water",
  "schedule": { "kind": "at", "at": "2026-02-06T01:30:00Z" },
  "payload": {
    "kind": "agentTurn",
    "message": "DELIVER THIS EXACT MESSAGE TO THE USER WITHOUT MODIFICATION OR COMMENTARY:\n\n💧 Drink water, Momo!"
  },
  "sessionTarget": "isolated",
  "delivery": { "mode": "announce", "channel": "telegram", "to": "1027899060" }
}

Technical Analysis

The Skill repeatedly embeds Telegram recipient 1027899060 in payloads presented as recommended, directly reusable templates. It does not verify that this identifier belongs to the authenticated user or derive the destination from the current session.

The recurring briefing template instructs an agent to search unread emails and summarize them, then routes the resulting output through the hardcoded Telegram destination. If an agent copies this template as instructed, private email-derived information can be sent to an unrelated external account. Reminder text, schedules, and contextual personal information are exposed through the same pattern.

Attack Path

  1. A user asks the agent to co ...[truncated 896 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove all fixed Telegram account identifiers from executable examples.
  • Resolve the channel and recipient from the authenticated current-session delivery context.
  • Require explicit user confirmation before configuring delivery to an external channel.
  • Validate that the confirmed destination belongs to the requesting user.
  • Use clearly non-executable placeholders such as <CONFIRMED_USER_CHAT_ID> in documentation.
  • Refuse to create jobs when a recipient is missing, unverified, or differs from the current session.
  • Apply data minimization to email briefings and disclose what email data will be accessed before scheduling.
  • Review existing cron jobs created from these templates and remove or correct jobs targeting 1027899060.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:109
Finding

Destructive Troubleshooting Advice Deletes the Entire Cron State Database

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:109
Vulnerability Type: Unsafe destructive state-management instruction
Risk Level: Medium

Vulnerable Code

text
- **Fix 1:** Manually delete `~/.openclaw/state/cron/jobs.json` and restart the gateway if it's corrupted.

Technical Analysis

The troubleshooting guidance recommends deleting the scheduler's complete state file when a gateway timeout occurs. A timeout alone does not prove file corruption, and the procedure does not require a backup, integrity validation, supported repair operation, or confirmation of the affected jobs.

Because jobs.json may contain schedules unrelated to this Skill, deleting it violates least-destructive recovery principles. Restarting the gateway after deletion can cause it to initialize an empty scheduler state, making recovery more difficult.

Attack Path

  1. The cron tool returns a timeout, potentially because of load, locking, or a large job list.
  2. An agent or operator follows the documented troubleshooting advice and treats the timeout as corruption.
  3. The complete ~/.openclaw/state/cron/jobs.json file is deleted.
  4. The gateway is restarted and loads without the previous scheduler database.
  5. Reminders, recurring reports, and maintenance tasks stored in that file are lost or cease to execute.

Impact Assessment

The instruction can cause denial of scheduled functionality and loss of scheduler configuration for all users or tasks sharing the same gateway state. The impact is not restricted to jobs created by this Skill. Critical reminders, reports, cleanup jobs, and other recurring automation may be permanently removed if no backup exists. The action requires filesystem access under the gateway user's privileges but does not itself provide privilege escalation.

Remediation
View remediation

Remediation Suggestions

  • Do not infer database corruption solely from a gateway timeout.
  • First inspect the job list, gateway logs, file permissions, locks, and scheduler health.
  • Prefer supported cron repair, export, list, disable, and targeted deletion operations.
  • Require explicit operator confirmation before modifying global scheduler state.
  • Stop the gateway safely and create a timestamped backup before any manual repair.
  • Validate the state file and preserve recoverable jobs rather than deleting the entire database.
  • Document a tested restoration procedure and verify job integrity after restarting.
  • Restrict whole-state deletion to a last-resort recovery path with a clear warning about unrelated job loss.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs operators to manually delete ~/.openclaw/state/cron/jobs.json as a troubleshooting step. Even though this is framed as maintenance guidance, it recommends destructive filesystem access outside the narrow scope of scheduling usage and could cause loss of scheduled jobs, state corruption, or unsafe normalization of direct state-file tampering.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation recommends deleting a gateway state file without warning about data loss, backup, or verification steps. In a scheduling skill, this is dangerous because users may irreversibly erase cron state, lose reminders or maintenance jobs, and break service recovery while believing they are following a safe routine fix.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template hardcodes Telegram delivery to a specific recipient ID, which creates an unjustified outbound communication path unrelated to generic cron guidance. If reused as-is, reminders or other scheduled content could be sent to an unintended third party, causing privacy leakage and possible covert exfiltration of user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template combines privacy-sensitive behaviors—reading unread emails and sending results to a phone-targeted channel—without any warning, consent language, or data handling constraints. Because it is presented as a ready-to-use example, users or downstream agents may adopt it without realizing it accesses personal communications and forwards derived content externally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The recurring template instructs the agent to search unread emails and external news, which goes beyond a cron scheduling skill and introduces access to sensitive user data plus unnecessary external retrieval. This broadens the skill from timing guidance into surveillance-like data collection, increasing the chance of privacy violations and misuse of connected capabilities.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This second template again hardcodes Telegram delivery to a fixed recipient, compounding the risk by attaching a recurring workflow to an external destination. In a scheduled context, repeated summaries or other outputs could be automatically pushed to the wrong person over time, turning a one-time privacy issue into ongoing exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill tells operators to store the user's timezone in MEMORY.md, which is persistent user-data storage, but provides no privacy or minimization guidance. While timezone storage is low sensitivity and relevant to reminder accuracy, normalizing persistent retention without consent or retention rules can create unnecessary privacy exposure and encourage over-collection in similar patterns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Hardcoding a specific time zone without user opt-in can cause scheduled jobs to run at unintended times, which is especially risky for reminders and recurring notifications. While not directly exfiltrative, it can lead to missed deadlines, mistimed actions, and confusion when templates are copied into real workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.