Cron Creator 定时任务创建器

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed OpenClaw/Feishu scheduling helper that creates cron reminders, with no executable payloads or hidden install behavior found.

Install this if you want OpenClaw/Feishu cron reminders, but confirm the resolved timezone, recipient or chat, account, message, and recurrence before relying on each scheduled job. Specify a timezone explicitly if you are not operating in Asia/Shanghai.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger scope is very broad: nearly any future reminder or scheduled-task phrasing can activate the skill, without explicit guardrails for ambiguity, authorization, or confirmation. In a multi-agent/chat environment, this increases the chance of the agent creating unintended scheduled actions from casual conversation, misinterpreted intent, or quoted/example text.

Natural-Language Policy Violations

Medium
Confidence
84% confidence
Finding
The skill silently defaults all unspecified times to Asia/Shanghai, which can cause scheduled actions to run at the wrong real-world time for users in other locales. In a scheduling skill, timezone assumptions directly affect execution timing, so an incorrect default can lead to missed reminders, premature actions, or actions delivered to the wrong audience at inappropriate hours.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal