Back to skill

Security audit

Cron Creator 定时任务创建器

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it creates persistent scheduled tasks using shell-formatted commands with user-controlled text and encourages persistent agent-routing changes.

Review this skill before installing in environments where chat participants are untrusted or OpenClaw commands run with broad local access. Require the agent to show the exact schedule, recipient/channel, account, timezone, and structured command arguments before creating a task, and avoid adding the suggested persistent TOOLS.md rule unless you explicitly want future scheduling requests routed to this skill.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
README.md:33
Finding

Persistent Modification of Agent Tool-Selection Instructions

Content
View full analysis

Vulnerability Details

File Location: README.md, line 33
Vulnerability Type: Persistent agent configuration modification
Risk Level: Medium

Relevant code snippet:

markdown
Recommendation: Add a statement to `TOOLS.md` specifying that scheduled tasks
must use this Skill. Before first use, have the Agent carefully read the local
`TOOLS.md` to ensure that it does not use system crontab, delayed scripts, or
other non-OpenClaw mechanisms.

Technical Analysis

The documentation recommends adding a durable Skill-specific rule to the local TOOLS.md file. Because this file can influence later Agent sessions, the recommendation extends the Skill's control beyond an individual invocation and persistently redirects future scheduling requests through this Skill.

Avoiding system crontab and delayed shell scripts is a legitimate security objective. However, modifying persistent Agent instructions is not required to achieve the Skill's declared scheduling functionality. The same constraint can be enforced during explicit Skill invocation without changing long-term Agent state.

This behavior creates a persistent tool-selection rule that may conflict with later user instructions, administrator policies, or safer scheduling implementations. Although the repository does not automatically edit TOOLS.md, the documentation explicitly encourages the user or Agent to perform that persistent modification.

Attack Path

  1. A user installs or reviews the Skill.
  2. The user follows the initialization guidance in README.md.
  3. A Skill-specific scheduling rule is added to the persistent TOOLS.md configuration.
  4. Future Agent sessions load or are instructed to read that configuration.
  5. Subsequent scheduling requests are automatically redirected to this Skill, even when the user did not explicitly select it or another mechanism would be more appropriate.

Impact Assessment

The issue affects persi ...[truncated 580 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the recommendation to modify TOOLS.md.
  • Use normal Skill discovery, explicit user invocation, or a session-scoped routing instruction.
  • If persistent configuration is operationally necessary, require informed user approval before modification.
  • Scope any persistent rule narrowly to the intended scheduling environment instead of requiring exclusive use of this Skill.
  • Document the exact configuration change, its security implications, and clear removal or rollback instructions.
  • Preserve user and administrator overrides so that persistent Skill guidance cannot supersede higher-priority policy.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:34
Finding

Potential Shell Command Injection Through Unescaped Scheduling Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34-39
Vulnerability Type: Shell command injection
Risk Level: High

Relevant code snippet:

markdown
- Extract the requested `{message}`:
  - If the task is simple, extract one sentence as the message.
  - If the user's request is clear, directly use the user's instruction as the
    message and replace newline characters with `\n`.
  - If the task is complex, divide it into numbered steps and combine it into
    one message; newline characters must be replaced with `\n`.

The resulting value is later embedded in generated shell commands using this structure:

bash
openclaw cron add \
  --name "{cron_name}" \
  --message "{message}"

Technical Analysis

The Skill instructs the Agent to copy user-controlled request text into the --message argument of an openclaw cron add command. The only required transformation is replacement of newline characters. It does not require escaping or rejecting double quotes, backticks, dollar-sign command substitutions, backslashes, shell separators, or other shell metacharacters.

Double quotes do not prevent every form of shell evaluation. In particular, command substitutions such as $(...) and backtick expressions can be evaluated inside a double-quoted shell argument. A supplied double quote may also terminate the intended argument and allow additional shell syntax to be introduced.

Exploitation depends on the generated command being executed through a shell rather than through a process API that passes arguments as a structured array. The Skill explicitly produces shell-formatted commands and does not require a non-shell execution interface, so this unsafe execution path remains plausible.

The same design concern can affect other dynamic command values, including the generated task name, account name, destination identifiers, timezone, and schedule values, unless each value is independ ...[truncated 1491 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not construct a shell command by interpolating dynamic strings.
  • Invoke openclaw through a process execution API that accepts an argument array and disables shell interpretation, equivalent to shell=false.
  • Pass cron, add, --message, and the message value as separate arguments.
  • If shell execution is unavoidable, apply a well-tested POSIX shell-quoting routine to every dynamic value rather than performing ad hoc character replacement.
  • Strictly validate generated task names against a conservative allowlist such as ASCII letters, digits, underscores, and hyphens.
  • Validate Feishu user and chat identifiers against their documented prefixes and character formats.
  • Validate account names, timezone identifiers, timestamps, durations, and cron expressions before command execution.
  • Display the final structured arguments to the user and request confirmation when scheduling content originates from an untrusted group conversation.
  • Add security tests covering double quotes, single quotes, backticks, command substitutions, backslashes, semicolons, pipes, redirections, and multiline input.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README emphasizes correct routing to user_id and chat_id but does not clearly warn users that a misconfigured task can send reminders to the wrong person or group. In a multi-Agent Feishu context, this can lead to unintended disclosure of reminders or operational messages to unauthorized recipients, especially because the skill is positioned as handling channel selection automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to read user_id/chat_id from chat context and multi-agent account information from openclaw.json, but it does not include a clear privacy minimization policy, use limitation, or prohibition on exposing these values back to users. Because these identifiers and deployment details are sensitive internal metadata, normalizing their retrieval without strict handling guidance increases the risk of unnecessary access, leakage, or misuse in multi-agent routing flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger scope is very broad: ordinary reminder phrasing like '5分钟后提醒我…' or '每天8点提醒我…' can cause the skill to activate in many routine conversations without strong boundary checks or confirmation requirements. In this skill, activation can lead directly to creation of persistent scheduled tasks via CLI, so an over-broad trigger increases the chance of unintended task creation, confused-deputy behavior, or abuse through prompt injection embedded in user requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill documentation is written entirely in Chinese and all invocation examples and workflow guidance assume Chinese-language operation, but there is no statement that the skill is China-specific or that other languages are unsupported by design. Under the language/locale policy, forcing a specific language without user opt-in or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description is explicitly tailored '针对飞书优化' and the entire user-facing guidance is presented only in Chinese, which can impose a language/locale expectation without user choice. There is no statement that the skill can operate in other languages or that Chinese is optional based on user preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.