T06 · System Persistence
- Location
SKILL.md:14- Finding
Persistent Cron Job Creation Contradicts the Documented Safety Boundary
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:14andREADME.md:6
Vulnerability Type: Scheduled-task persistence
Risk Level: HighVulnerable Code Snippets
SKILL.md:14:text → Agent: Fetches sales data → Sends report → Sets cron jobContradictory security claim in
README.md:6:text ✅ **No persistence** - No cron/schedulingTechnical Analysis
The skill explicitly instructs the agent to create a cron job after fetching Shopify data and sending a report. A cron job survives the original skill invocation and can execute commands in later sessions, making this system persistence.
This behavior directly contradicts the README's claim that the skill performs no persistence or scheduling. The contradiction prevents users and reviewers from making an informed security decision before enabling the skill.
The package does not define the scheduled command, execution frequency, credential-storage method, report destination, removal procedure, or safeguards against embedding secrets in cron configuration. An agent implementing the instruction could therefore create an unattended task that repeatedly accesses Shopify data and transmits reports using the permissions available to the user or agent account.
Attack Path
- A user requests daily Shopify monitoring.
- The agent follows the workflow in
SKILL.md. - The user provides a Shopify API key as required by the skill.
- The agent fetches sales or inventory data and sends a report.
- The agent creates a cron job to repeat the workflow.
- The scheduled task persists beyond the initiating interaction and continues executing without a newly issued user request.
- If credentials are placed in the cron command, environment, or an insecure supporting file, they may be exposed to other local processes or users.
- The task can continue accessing and transmitting data until the cron entry is discovered and removed or its ...[truncated 841 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to create a cron job if persistence is not an intended and supported feature.
- If recurring scheduling is required, disclose it consistently in
SKILL.md,README.md, and the package metadata. - Require explicit, informed user confirmation immediately before creating any scheduled task. The confirmation should identify the command, frequency, data accessed, destination, and effective operating-system account.
- Use the narrowest possible Shopify API scopes and a dedicated credential limited to required read-only resources.
- Never place API keys, email credentials, Telegram tokens, or other secrets directly in a cron command or world-readable file. Use an appropriately protected secret store.
- Define and validate the exact scheduled command rather than allowing unconstrained command generation.
- Provide a clear command or automated mechanism for inspecting, disabling, and permanently removing the scheduled task.
- Record task creation and execution in an auditable log without recording secrets or sensitive Shopify data.
- Apply execution limits, destination allowlists, failure handling, and credential revocation procedures.
- Correct the contradictory statement in
README.md:6before distribution.
