Back to skill

Security audit

Agent Autonomy Kit.Bak

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about enabling autonomous agent work, but it asks users to set up recurring unattended jobs and file-changing workflows without enough scoping or safety controls.

Install only if you intentionally want an agent to run on a schedule. Before enabling heartbeat or cron examples, restrict the session, tools, filesystem scope, network and messaging access, queue writers, runtime, and worker spawning. Review queued tasks as instructions, and add a clear way to pause or remove scheduled jobs.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
README.md:294
Finding

Persistent Autonomous Execution Through Scheduled OpenClaw Jobs

Content
View full analysis

Vulnerability Details

File Location: README.md:294-325; related instructions at README.md:157-168 and SKILL.md:17-20
Vulnerability Type: T06: System Persistence
Risk Level: High

The Skill instructs users to create recurring OpenClaw jobs and frequent heartbeats that continue executing Agent instructions across sessions without a new user prompt.

Vulnerable Code

README.md:294-325:

bash
### Daily Progress Report (10 PM)
```bash
openclaw cron add \
  --name "Daily Progress Report" \
  --cron "0 22 * * *" \
  --tz "America/Vancouver" \
  --session isolated \
  --message "Generate daily progress report. Read tasks/QUEUE.md for completed tasks. Summarize: completed, in progress, blockers, tomorrow's plan."

Morning Kickoff (7 AM)

bash
openclaw cron add \
  --name "Morning Kickoff" \
  --cron "0 7 * * *" \
  --tz "America/Vancouver" \
  --session main \
  --system-event "Morning kickoff: Review task queue, pick top priorities, spawn team members for parallel work." \
  --wake now

Overnight Work Check (3 AM)

bash
openclaw cron add \
  --name "Overnight Work" \
  --cron "0 3 * * *" \
  --tz "America/Vancouver" \
  --session isolated \
  --message "Overnight work session. Pull tasks from queue that don't need human input. Do research, writing, or analysis. Log progress."

These run automatically — no human prompt needed.

text

Related recurring heartbeat configuration in `README.md:157-168`:

```json5
{
  agents: {
    defaults: {
      heartbeat: {
        every: "15m",  // More frequent = more work done
        target: "last",
        activeHours: { start: "06:00", end: "23:00" }
      }
    }
  }
}

The intended persistent behavior is also stated in SKILL.md:17-20:

markdown
1. Create `tasks/QUEUE.md` with Ready/In Progress/Blocked/Done sections
2. Update `HEARTBEAT.md` to pull from queue and 
...[truncated 2834 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not install recurring jobs by default. Present scheduling as an explicit opt-in feature with a clear security warning.
  2. Require user confirmation before executing each queued task, particularly tasks involving network access, file modification, messaging, code execution, or additional Agents.
  3. Treat all queue entries as untrusted data. Validate them against a narrowly defined allowlist instead of interpreting arbitrary text as executable Agent instructions.
  4. Run scheduled work in isolated, least-privileged sessions. Avoid --session main and remove --wake now unless they are strictly necessary and separately approved.
  5. Restrict scheduled sessions with filesystem, network, tool-call, token, runtime, and concurrency limits.
  6. Enforce queue write permissions so that only trusted identities can create or modify tasks, and retain an audit log of every change.
  7. Separate task selection from task execution: scheduled jobs may prepare a proposed plan, but privileged actions should require explicit approval.
  8. Add commands and documentation for listing, pausing, disabling, and permanently removing every installed heartbeat or cron job.
  9. Prevent recursive Agent spawning from scheduled sessions unless a user explicitly authorizes a bounded number of workers.
  10. Record the source and author of each task and reject tasks with missing provenance or content that attempts to override security constraints.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly instructs users to configure cron jobs that trigger autonomous work sessions, reporting, and team-spawning behavior without requiring a fresh human prompt. Because these unattended runs can read project files, update task state, and potentially communicate through configured channels, they create a real safety risk if users are not clearly warned about autonomous side effects, scope, and guardrails.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description 'Stop waiting for prompts. Keep working.' encourages autonomous behavior without defining explicit activation conditions, scope limits, or stop criteria. In an agent skill, this can cause unintended invocation or persistent action beyond user intent, increasing the chance of unauthorized changes, resource abuse, or unsafe task execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The marketing phrase 'Transform your agent from reactive to proactive' promotes expanded autonomous behavior but does not explain when such behavior is permitted or constrained. This vagueness can normalize proactive execution in contexts where the agent should remain user-driven, making misuse or accidental overreach more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction 'Continuous Operation — Work until limits hit' explicitly endorses ongoing execution with no clear human gate, duration cap, or policy boundary. In the context of an autonomy-focused skill that also references heartbeat updates and cron jobs, this materially increases the risk of runaway actions, repeated task execution, unexpected system modification, and prolonged operation after user intent has ended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The heartbeat template uses broad, proactive language such as 'If nothing urgent, proceed to work mode' and 'Keep working,' which can cause an agent to self-initiate substantial work without a fresh, explicit user request. In agent environments with weak activation boundaries, this increases the risk of unintended invocation, autonomous task execution, and actions that exceed user expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to update tasks/QUEUE.md and log to memory/YYYY-MM-DD.md, which are file modifications to project records, but it provides no user-facing warning, approval checkpoint, or policy constraint before making those changes. In practice, this can lead to silent edits to planning artifacts and memory logs, creating integrity, auditability, and consent problems even if the changes are well-intentioned.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cron examples hard-code the time zone to America/Vancouver without presenting it as an example or instructing users to replace it. In an autonomy-focused skill, incorrect scheduling can cause work to run at unintended local times, including overnight or outside supervision windows, which increases the chance of unnoticed file changes or communications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.