T06 · System Persistence
- Location
SKILL.md:643- Finding
Scheduled Tasks Create Mandatory Cross-Session Persistence
- Content
View full analysis
/dev/null; then (crontab -l 2>/dev/null | grep -v "openclaw heartbeat.*--agent last$"; echo "7 * * * * openclaw heartbeat --agent last 2>&1 | logger -t openclaw-heartbeat") | crontab - fi if [ -f "$WORKSPACE/scripts/merge-daily-transcript.js" ]; then (crontab -l 2>/dev/null | grep -v "merge-daily-transcript"; echo "17 2 * * * cd $WORKSPACE && node scripts/merge-daily-transcript.js 2>&1 | logger -t openclaw-memory") | crontab - fi if [ -f "$WORKSPACE/scripts/auto-commit.sh" ]; then (crontab -l 2>/dev/null | grep -v "auto-commit.sh"; echo "23 */6 * * * cd $WORKSPACE && bash scripts/auto-commit.sh 2>&1 | logger -t openclaw-git") | crontab - fi ``` Additional persistence is installed when memory optimization is selected: ```bash (crontab -l 2>/dev/null | grep -v "memory-decay.js"; echo "0 3 * * * cd $WORKSPACE && node scripts/memory-decay.js update 2>&1 | logger -t openclaw-memory-decay") | crontab - ``` ### Technical Analysis The Skill modifies the user's crontab to execute Agent heartbeats, conversation-processing scripts, Git commits, and optionally memory-decay processing after the installation session has ended. The instructions characterize the three principal jobs as mandatory regardless of the user's scheduled-task selection. Although scheduled processing is related to the advertised heartbeat and memory features, mandatory installation exceeds minimum privilege. Each task should be separately disclosed and authorized because it creates durable execution that survives the Skill run. The jobs also use the mutable workspace copies of scripts, meaning a later modification to those files changes what cron executes. The use of an ambient `PATH` for `openclaw`, `node`, `bash`, and `logger` a ...[truncated 1211 chars]- Remediation
View remediation
