T06 · System Persistence
- Location
SKILL.md:25- Finding
Persistent Unattended Replacement of Agent and Skill Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it sets up unattended daily updates that can change Clawdbot and every installed skill without per-update review.
Install only if you intentionally want a recurring background task that can modify Clawdbot and all installed skills. Prefer dry-run notifications, reviewing each update before applying it, limiting updates to trusted skills, avoiding `sudo` or forced updates for routine recovery, and confirming you know how to remove the cron job.
SKILL.md:25Persistent Unattended Replacement of Agent and Skill Code
references/agent-guide.md:19Persistent Update Helper Suppresses Failures and Encourages Unsafe Recovery
The command clawdhub update --all causes the agent environment to self-modify by pulling and applying updates to all installed skills, which can change future agent behavior without granular review. In this context it is especially dangerous because it is combined with unattended scheduling, so new or compromised skill releases could be deployed automatically and persistently.
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")
# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"
The skill explicitly instructs users to configure unattended daily updates for both the core tool and all installed skills, which can cause automatic code changes without review or rollback planning. In a skill ecosystem, this increases supply-chain and stability risk because any compromised, malicious, or simply broken upstream release could be pulled and applied automatically across the installation.
Creating a helper script at a stable path under ~/.clawdbot/scripts/auto-update.sh introduces session persistence by establishing a reusable artifact intended for future automated execution. In combination with the later cron instructions, this persistence increases risk because the update logic remains on disk and can continue making changes over time or be modified and reused unexpectedly.
bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"
## Step 2: Create the Update Script (Optional)
For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:
The helper script creates persistent files under ~/.clawdbot/logs and performs update and migration commands, yet the guide presents it as an optional setup step without clearly disclosing these filesystem and software-modifying side effects up front. This is risky because users may authorize or copy the script without understanding that it writes logs, changes installed components, and runs maintenance commands automatically.
The guide instructs the agent to create a daily cron-driven auto-update routine that will repeatedly modify the installed bot and all skills in the background, but it does not prominently warn about the ongoing side effects or require explicit user acknowledgment at execution time. This is dangerous because it normalizes persistent, unattended system changes and can silently introduce new code or behavior after initial setup.
The setup command specifies --tz "America/Los_Angeles", which imposes a locale-specific configuration in the primary usage example. The document does not clearly tell the user to choose their own timezone at setup time or label this value as merely illustrative.
The markdown example states that daily updates will run at "4:00 AM (America/Los_Angeles)", which implies a fixed locale/time zone in user-facing text. Under the policy, forcing a specific locale without user opt-in can be a natural-language policy violation unless it is clearly justified or optional.
No suspicious patterns detected.