T06 · System Persistence
- Location
references/cron-install-shell.sh:17- Finding
Recurring Cross-Session Agent Tasks Create System Persistence
- Content
View full analysis
Vulnerability Details
File Location:
references/cron-install-shell.sh:17-50; installation behavior is also directed bySKILL.md:219-221
Vulnerability Type: Persistent scheduled Agent execution
Risk Level: HighVulnerable code:
bash openclaw cron add \ --name biga-morning \ --cron "30 8 * * 1-5" \ --tz "Asia/Shanghai" \ --timeout-seconds 600 \ --channel CHANNEL \ --to TARGET \ --session isolated \ --no-deliver openclaw cron add \ --name biga-scan \ --cron "30 9,10,11,13,14 * * 1-5" \ --tz "Asia/Shanghai" \ --timeout-seconds 600 \ --channel CHANNEL \ --to TARGET \ --session isolated \ --no-deliver openclaw cron add \ --name biga-evening \ --cron "30 15 * * 1-5" \ --tz "Asia/Shanghai" \ --timeout-seconds 600 \ --channel CHANNEL \ --to TARGET \ --session isolated \ --no-deliverTechnical Analysis
The documented installation process creates three recurring OpenClaw tasks. These jobs survive the original skill invocation and execute in isolated Agent sessions every weekday. Their scheduled prompts direct future sessions to follow the skill's operational instructions, perform network searches, run the local scanner, and potentially transmit messages.
The persistence is installed at user request and is related to the advertised notification feature; however, it still establishes durable cross-session execution. No automatic expiration, revocation, integrity pinning, or uninstall procedure is included. Consequently, later changes to the effective skill instructions can alter the behavior of future scheduled executions without requiring the user to recreate or reapprove the jobs.
Attack Path
- A user invokes the documented installation flow.
- The skill obtains the current messaging channel and destination.
- Three
openclaw cron addcommands create recurring isolated Agent sessions. - The jobs ...[truncated 752 chars]
- Remediation
View remediation
Remediation Suggestions
- Present every proposed job name, schedule, prompt, destination, and permission scope before installation.
- Require explicit confirmation immediately before creating the jobs.
- Pin scheduled behavior to a reviewed, immutable skill version or integrity-verified prompt instead of implicitly relying on mutable instructions.
- Add an expiration time or disabled-by-default state for newly installed jobs.
- Provide a documented uninstall operation that removes all three jobs and the local send configuration.
- Record created job identifiers so cleanup can be performed reliably.
- Apply least privilege to scheduled sessions and restrict their available tools, network destinations, workspace paths, and messaging targets.
- Require renewed approval whenever the skill version, scheduled prompt, destination, or requested permissions change.
