T06 · System Persistence
- Location
SKILL.md:82- Finding
Persistent Scheduled Execution Through User Crontab
- Content
View full analysis
> ~/.openclaw/logs/micro-sync.log 2>&1 0 1 * * * ~/.openclaw/shared/daily-wrapup.sh >> ~/.openclaw/logs/daily-wrapup.log 2>&1 0 3 * * 0 ~/.openclaw/shared/weekly-compound.sh >> ~/.openclaw/logs/weekly-compound.log 2>&1 ``` ### Technical Analysis The installation procedure copies executable scripts into the user's persistent OpenClaw directory and instructs the user to register three recurring cron jobs. These jobs survive the installation session and repeatedly modify the Agent's heartbeat state. Scheduled execution is related to the declared automatic memory-maintenance functionality. However, it exceeds the privileges required for on-demand memory management and creates an enduring execution channel. The scripts are executed with the permissions of the user who owns the crontab. The cron commands execute mutable files under `~/.openclaw/shared/` without integrity verification. If another process, compromised Skill, or account actor can modify those files after installation, the next scheduled invocation will execute the replacement content with the user's permissions. ### Attack Path 1. The user follows the installation instructions and copies the scripts into `~/.openclaw/shared/`. 2. The user grants execute permission to all shell scripts in that directory through the wildcard command. 3. The user registers the three cron entries. 4. The jobs continue executing across sessions at their configured intervals. 5. An actor capable of modifying a scheduled script can replace or append shell commands to it. 6. Cron sub ...[truncated 570 chars]- Remediation
View remediation
