T06 · System Persistence
- Location
SKILL.md:84- Finding
Recurring Cron Jobs Establish Cross-Session Persistence
- Content
View full analysis
> ~/.openclaw/logs/micro-sync.log 2>&1 0 1 * * * ~/.openclaw/shared/daily-wrapup.sh >> ~/.openclaw/logs/daily-wrapup.log 2>&1 0 3 * * 0 ~/.openclaw/shared/weekly-compound.sh >> ~/.openclaw/logs/weekly-compound.log 2>&1 ``` ### Technical Analysis The installation instructions copy three scripts into a persistent user directory, grant them executable permissions, and register recurring user-level cron jobs. These tasks survive the original Skill run and continue executing under the installing user's account. Scheduling is directly related to the declared automatic memory-maintenance functionality and is not concealed. Nevertheless, persistent cron registration exceeds the privileges required for an on-demand memory-management operation. The configuration also lacks an on-demand default, explicit lifecycle controls, an uninstall procedure, integrity checks, and protections against subsequent replacement of the installed scripts. Because cron executes scripts by path, any process able to modify files under `~/.openclaw/shared/` could alter what the recurring jobs execute. ### Attack Path 1. A user follows the Skill installation instructions. 2. The three scripts are copied into `~/.openclaw/shared/` and made executable. 3. The user installs the supplied crontab entries. 4. Cron invokes the scripts repeatedly after the installation session has ended. 5. Each execution modifies persistent OpenClaw state through `HEARTBEAT.md`. 6. If an installed script is later replaced or modified, cron executes the changed content with the user's priv ...[truncated 439 chars]- Remediation
View remediation
