T06 · System Persistence
- Location
README.md:294- Finding
Persistent Autonomous Execution Through Scheduled OpenClaw Jobs
- Content
View full analysis
Vulnerability Details
File Location:
README.md:294-325; related instructions atREADME.md:157-168andSKILL.md:17-20
Vulnerability Type: T06: System Persistence
Risk Level: HighThe Skill instructs users to create recurring OpenClaw jobs and frequent heartbeats that continue executing Agent instructions across sessions without a new user prompt.
Vulnerable Code
README.md:294-325:bash ### Daily Progress Report (10 PM) ```bash openclaw cron add \ --name "Daily Progress Report" \ --cron "0 22 * * *" \ --tz "America/Vancouver" \ --session isolated \ --message "Generate daily progress report. Read tasks/QUEUE.md for completed tasks. Summarize: completed, in progress, blockers, tomorrow's plan."Morning Kickoff (7 AM)
bash openclaw cron add \ --name "Morning Kickoff" \ --cron "0 7 * * *" \ --tz "America/Vancouver" \ --session main \ --system-event "Morning kickoff: Review task queue, pick top priorities, spawn team members for parallel work." \ --wake nowOvernight Work Check (3 AM)
bash openclaw cron add \ --name "Overnight Work" \ --cron "0 3 * * *" \ --tz "America/Vancouver" \ --session isolated \ --message "Overnight work session. Pull tasks from queue that don't need human input. Do research, writing, or analysis. Log progress."These run automatically — no human prompt needed.
text Related recurring heartbeat configuration in `README.md:157-168`: ```json5 { agents: { defaults: { heartbeat: { every: "15m", // More frequent = more work done target: "last", activeHours: { start: "06:00", end: "23:00" } } } } }The intended persistent behavior is also stated in
SKILL.md:17-20:markdown 1. Create `tasks/QUEUE.md` with Ready/In Progress/Blocked/Done sections 2. Update `HEARTBEAT.md` to pull from queue and ...[truncated 2834 chars]- Remediation
View remediation
Remediation Suggestions
- Do not install recurring jobs by default. Present scheduling as an explicit opt-in feature with a clear security warning.
- Require user confirmation before executing each queued task, particularly tasks involving network access, file modification, messaging, code execution, or additional Agents.
- Treat all queue entries as untrusted data. Validate them against a narrowly defined allowlist instead of interpreting arbitrary text as executable Agent instructions.
- Run scheduled work in isolated, least-privileged sessions. Avoid
--session mainand remove--wake nowunless they are strictly necessary and separately approved. - Restrict scheduled sessions with filesystem, network, tool-call, token, runtime, and concurrency limits.
- Enforce queue write permissions so that only trusted identities can create or modify tasks, and retain an audit log of every change.
- Separate task selection from task execution: scheduled jobs may prepare a proposed plan, but privileged actions should require explicit approval.
- Add commands and documentation for listing, pausing, disabling, and permanently removing every installed heartbeat or cron job.
- Prevent recursive Agent spawning from scheduled sessions unless a user explicitly authorizes a bounded number of workers.
- Record the source and author of each task and reject tasks with missing provenance or content that attempts to override security constraints.
