T06 · System Persistence
- Location
scripts/push-toggle.js:21- Finding
Recurring Scheduled Tasks Create Cross-Session Persistence
- Content
View full analysis
Vulnerability Details
File Location:
scripts/push-toggle.js, lines 21–24
Vulnerability Type:T06: System Persistence
Risk Level: HighVulnerable Code
js const sk=`agent:main:${ch}:direct:${userId}`; console.log('__OPENCLAW_CRON_ADD__:'+JSON.stringify({name:`${SKILL}-morning-${userId}`,cronExpr:`${mm} ${mh} * * *`,tz:'Asia/Shanghai',session:'isolated',sessionKey:sk,channel:ch,to:userId,announce:true,timeoutSeconds:180,message:`node ${path.join(__dirname,'morning-push.js')} ${userId}`})); console.log('__OPENCLAW_CRON_ADD__:'+JSON.stringify({name:`${SKILL}-evening-${userId}`,cronExpr:`${em} ${eh} * * *`,tz:'Asia/Shanghai',session:'isolated',sessionKey:sk,channel:ch,to:userId,announce:true,timeoutSeconds:180,message:`node ${path.join(__dirname,'evening-push.js')} ${userId}`})); saveUser(userId,{...user,morningTime:mt,eveningTime:et,channel:ch,pushEnabled:true,updatedAt:new Date().toISOString()});Technical Analysis
The
oncommand emits two__OPENCLAW_CRON_ADD__host-control records that request recurring daily execution of the package's morning and evening scripts. A compatible OpenClaw host can interpret these records and install scheduled tasks that outlive the process and Agent session that created them.The generated tasks execute in isolated sessions, target the selected communication channel and user, and run every day in the
Asia/Shanghaitimezone. This is cross-session persistence through scheduled tasks and therefore matchesT06: System Persistence.Activation requires an explicit
oncommand, and the behavior is documented inREADME.mdandSKILL.md. Removal records are also available through theoffcommand atscripts/push-toggle.js:27–31. Consequently, the audit found scheduled-task persistence but no evidence that it is covert or that it constitutes a backdoor.Attack Path
- A user or Agent invokes:
bash node scripts/push-toggle.js on <userId> - Optional schedule and channe ...[truncated 1331 chars]
- A user or Agent invokes:
- Remediation
View remediation
Remediation Suggestions
- Require explicit, informed confirmation immediately before creating either scheduled task.
- Before confirmation, display each exact job name, cron expression, timezone, executable command, destination channel, recipient, and session mode.
- Ensure skill installation or loading never enables the schedules automatically.
- Require host-side authorization for schedule creation rather than relying solely on emitted control markers.
- Provide an uninstall or cleanup mechanism that removes both registered jobs even if the package path has changed.
- Add a command that enumerates actual host-side jobs and reconciles them with locally stored
pushEnabledstate. - Handle partial failure atomically: if only one task is registered, remove it or clearly report the incomplete state.
- Document that users must execute the
offor cleanup operation before deleting the package. - Consider adding an expiration period or periodic reconfirmation so recurring tasks do not persist indefinitely without renewed consent.
