Back to skill

Security audit

Pulse Board

Security checks for vulnerabilities and agentic risk

Overview

Pulse Board is a disclosed cron digest tool, but it has review-worthy risks around persistent cron changes, broad secrets-file execution, unsafe cron construction, and sending log content to configured agents or messaging services.

Review this skill carefully before installing. It is not evidenced as malicious, but it can modify your user crontab, persist scheduled commands, source a shared secrets file as shell code, store notification credentials in plaintext config, and send operational log content to an OpenClaw agent or messaging service. Use it only with trusted cron jobs, a local or low-privilege summarization agent, tightly permissioned config/secrets files, and logs that do not contain secrets or sensitive incident data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
plug.sh:44
Finding

Command Injection Through Unsafe Python Heredoc and Cron Construction

Content
View full analysis
"$PULSE_HOME/registry/${skill_safe}.conf" <
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
digest-agent.sh:16
Finding

Unconditional Execution of a Shared Secrets File

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
digest-agent.sh:88
Finding

Stored Prompt Injection Through Untrusted Digest Log Messages

Content
View full analysis
> "$PENDING_LOG" ``` ```bash PROMPT="You are writing a brief operational digest for a sysadmin. Below are cron job outcomes from the last 12 hours. Write: 1. One opening sentence on overall system health (casual, factual) 2. One bullet per skill: what ran, how many times, outcome 3. If errors or warnings exist, expand with relevant log lines Rules: plain text only — no asterisks, backticks, underscores, or any Markdown. No title line. No sign-off. No padding. Do not invent information. Do not include the status counts line. Raw log: $(cat "$PENDING_LOG")" AGENT_RESPONSE="$(timeout "$LLM_TIMEOUT" openclaw agent \ --agent "$LLM_AGENT" --message "$PROMPT" --json 2>/dev/null)" \ && CALL_OK=true || CALL_OK=false ``` ### Technical Analysis `log-append.sh` accepts arbitrary message text and writes it directly to `pending.log`. It does not enforce a single line, impose a length limit, remove control characters, or distinguish trusted fields from untrusted content. `digest-agent.sh` subsequently concatenates the entire log into an instruction-bearing prompt. A malicious message can therefore contain directives intended for the OpenClaw agent, such as requests to ignore the summarization rules, conceal errors, emit attacker-selected content, or invoke capabilities exposed to the selected agent. The existing prompt asks the agent not to invent information, but it does not provide a strong structured separation between trusted instructions and untrusted log data. This is a stored attack because the malicious content persists in `pending.log` until scheduled digest processing. ...[truncated 1042 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
install.sh:218
Finding

Plaintext Delivery Credentials Created Without Restrictive Permissions

Content
View full analysis
"$CONFIG_FILE" <
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
unplug.sh:50
Finding

Overbroad Crontab Removal Through Unanchored Pattern Matching

Content
View full analysis
/dev/null || true)" if echo "$EXISTING_CRON" | grep -q "pulse-board:$SKILL_SAFE"; then echo "$EXISTING_CRON" | grep -v "pulse-board:$SKILL_SAFE" | crontab - green " ✓ Cron entry removed" else yellow " · No cron entry found for: $SKILL_SAFE" fi ``` ### Technical Analysis The script removes every crontab line containing the unanchored regular expression `pulse-board:$SKILL_SAFE`. The match is not constrained to the exact terminal tag generated for the selected skill. For example, unplugging a skill normalized as `foo` also matches and removes a line tagged `pulse-board:foo-bar`. Because the whole crontab is filtered and then replaced, all matching lines are deleted in one operation. The implementation also does not check the final `crontab -` result or maintain a rollback copy before replacing the existing crontab. ### Attack Path 1. Two jobs are registered with overlapping normalized identifiers, such as `foo` and `foo-bar`. 2. The user runs `unplug.sh --skill foo`. 3. `grep -v "pulse-board:foo"` matches both tags. 4. Both scheduled entries are removed from the generated crontab. 5. The shortened crontab replaces the user’s existing crontab, silently disabling the unrelated `foo-bar` job. ### Impact Assessment This can cause loss of availability for unrelated Pulse Board jobs and potentially any manually created line containing the same substring. The operation affects the current user’s crontab only and does not require or obtain root privileges. Its practical impact depends on the importance of the deleted scheduled tasks. ]]>
Remediation
View remediation
``` 2. Anchor and escape the identifier rather than treating it as an unrestricted regular expression. 3. Prefer exact string comparison in Python instead of `grep`. 4. Back up the original crontab before replacement. 5. Check the exit status of `crontab -` and restore the backup if installation fails. 6. Report the exact lines proposed for deletion and request confirmation when more than one line matches. 7. Add tests for overlapping identifiers such as `foo`, `foo-bar`, and `foo-bar-baz`. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (26)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · CHANGELOG.md (reported line 92)May include surrounding context.

md
mmary, not the raw log
- Raw log accessible on demand via `last-digest.md` or by asking your agent

---

## [1.0.5] - 2026-03-09

### Fixed / Security
- `install.sh` secrets env patch is now **explicit opt-in**: the installer
  shows exactly which keys are missing and why, then asks for confirmation
  before appending anything. Nothing is written to the secrets env file
  silently.
- `install.sh` crontab change is now **announced before it happens**: the
  installer prints the exact entries it will add and asks for confirmation.
- `plug.sh` `wrap_cmd` now carries an explicit comment explaining that the
  secrets env is sourced in the cron shell context only — it is never read,
  parsed, logged, or transmitted by `plug.sh` itself.
- `_meta.json` now fully declares `requires.binaries`, `requires.env_vars`,
  `filesystem.creates/reads/modifies`, `network.external_endpoints`, and
  `credentials` — eliminating the metadata/behavior mismatch flagged by the
  OpenClaw security scanner.
-

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about a digest/summary pipeline: collecting scheduled skill outcomes, composing human-readable summaries with an agent, delivering them to messaging platforms, and installation/plugging workflows. The supplied code does none of that. Instead, it is an unplug.sh utility focused on removing a skill's registry entry and cron schedule. This is a materially different primary purpose and involves a capability not represented in the declared description: uninstalling/disconnecting scheduled skills by modifying config files and the user's crontab. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
`deliver.sh` |
| `~/.pulse-board/registry/<skill>.conf` | Written by `plug.sh`, removed by `unplug.sh` |

### Crontab
| Script | Action |
|--------|--------|
| `install.sh` | Adds two digest cron entries (`pulse-board-morning`, `pulse-board-evening`) |
| `plug.sh` | Adds one wrapped cron entry per skill (`# pulse-board:<skill>`) |
| `unplug.sh` | Removes the matching cron entry for a skill |

All crontab writes are done via `python3 subprocess`. Existing entries are never modified.

### Secrets env file
`install.sh` will ask for explicit confirmation before appending anything.
It may add `LLM_API_KEY=ollama` and `OPENCLAW_WORKSPACE=<path>` if missing.

### Network
- **Telegram:** `POST https://api.telegram.org/bot<token>/sendMessage`
- **Discord:** `POST <your webhook URL>`
- **OpenClaw agent:** `openclaw agent --agent <id> --message <prompt> --json` (local gateway call)
  ⚠️ The raw log is included in the prompt. If your agent uses a remote/cloud LLM, log content will be transmitt

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

Accessing and sourcing a shared secrets file grants this script visibility into credentials beyond those strictly required for delivery. Because source executes shell content, a compromised or overly broad secrets file can lead to credential exposure or arbitrary code execution in the context of this script.

Content

Scanner excerpt · deliver.sh (reported line 13)May include surrounding context.

sh
PULSE_HOME="${PULSE_HOME:-$HOME/.pulse-board}"
CONFIG_FILE="$PULSE_HOME/config/pulse.yaml"

[[ -f "$HOME/.openclaw/shared/secrets/openclaw-secrets.env" ]] && \
  { set +u; source "$HOME/.openclaw/shared/secrets/openclaw-secrets.env"; set -u; }

# ── Helpers ───────────────────────────────────────────────────────────────────

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The sourcing operation completes on this line, meaning all variables and any embedded shell statements from the shared secrets file are imported into the runtime. In a skill ecosystem, this increases blast radius because a simple delivery helper now depends on and can be influenced by a central secret-bearing shell file.

Content

Scanner excerpt · deliver.sh (reported line 14)May include surrounding context.

sh
CONFIG_FILE="$PULSE_HOME/config/pulse.yaml"

[[ -f "$HOME/.openclaw/shared/secrets/openclaw-secrets.env" ]] && \
  { set +u; source "$HOME/.openclaw/shared/secrets/openclaw-secrets.env"; set -u; }

# ── Helpers ───────────────────────────────────────────────────────────────────
g() { printf "\033[0;32m%s\033[0m\n" "$*" >&2; }

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · _meta.json (reported line 52)May include surrounding context.

json
PULSE_HOME="${PULSE_HOME:-$HOME/.pulse-board}"
CONFIG_FILE="$PULSE_HOME/config/pulse.yaml"

[[ -f "$HOME/.openclaw/shared/secrets/openclaw-secrets.env" ]] && \
  { set +u; source "$HOME/.openclaw/shared/secrets/openclaw-secrets.env"; set -u; }

# ── Helpers ───────────────────────────────────────────────────────────────────

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · _meta.json (reported line 57)May include surrounding context.

json
PULSE_HOME="${PULSE_HOME:-$HOME/.pulse-board}"
CONFIG_FILE="$PULSE_HOME/config/pulse.yaml"

[[ -f "$HOME/.openclaw/shared/secrets/openclaw-secrets.env" ]] && \
  { set +u; source "$HOME/.openclaw/shared/secrets/openclaw-secrets.env"; set -u; }

# ── Helpers ───────────────────────────────────────────────────────────────────

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · digest-agent.sh (reported line 16)May include surrounding context.

sh
PULSE_HOME="${PULSE_HOME:-$HOME/.pulse-board}"
CONFIG_FILE="$PULSE_HOME/config/pulse.yaml"

[[ -f "$HOME/.openclaw/shared/secrets/openclaw-secrets.env" ]] && \
  { set +u; source "$HOME/.openclaw/shared/secrets/openclaw-secrets.env"; set -u; }

# ── Helpers ───────────────────────────────────────────────────────────────────

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · digest-agent.sh (reported line 17)May include surrounding context.

sh
PULSE_HOME="${PULSE_HOME:-$HOME/.pulse-board}"
CONFIG_FILE="$PULSE_HOME/config/pulse.yaml"

[[ -f "$HOME/.openclaw/shared/secrets/openclaw-secrets.env" ]] && \
  { set +u; source "$HOME/.openclaw/shared/secrets/openclaw-secrets.env"; set -u; }

# ── Helpers ───────────────────────────────────────────────────────────────────

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 172)May include surrounding context.

sh
PULSE_HOME="${PULSE_HOME:-$HOME/.pulse-board}"
CONFIG_FILE="$PULSE_HOME/config/pulse.yaml"

[[ -f "$HOME/.openclaw/shared/secrets/openclaw-secrets.env" ]] && \
  { set +u; source "$HOME/.openclaw/shared/secrets/openclaw-secrets.env"; set -u; }

# ── Helpers ───────────────────────────────────────────────────────────────────

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · digest-agent.sh (reported line 46)May include surrounding context.

sh
if [[ -f "$LOCK" ]]; then
  AGE=$(( $(date +%s) - $(date -r "$LOCK" +%s 2>/dev/null || echo 0) ))
  [[ $AGE -lt 3600 ]] && { y "digest-agent: already running (${AGE}s). Exiting."; exit 0; }
  y "digest-agent: removing stale lock (${AGE}s)."; rm -f "$LOCK"
fi
touch "$LOCK"; trap 'rm -f "$LOCK"' EXIT

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · install.sh (reported line 9)May include surrounding context.

sh
#!/usr/bin/env bash
# Pulse Board — install.sh
# Interactive installer. Run once. Does everything.
# No sudo. No root. No system path writes outside ~/.pulse-board/
#
# What this script does — in full:
#   1. Creates ~/.pulse-board/{config,logs,registry,locks}
#   2. Writes ~/.pulse-board/config/pulse.yaml (once — never overwrites)
#   3. Adds two digest cron entries to your user crontab
#   4. Optionally appends LLM_API_KEY and OPENCLAW_WORKSPACE to your
#      secrets env file — only if you confirm at the prompt.
#
# Nothing is written silently. Every change is announced before it happens.

set -uo pipefail

SKILL_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
PULSE_HOME="${PULSE_HOME:-$HOME/.pulse-board}"

# ── UI helpers ────────────────────────────────────────────────────────────────
green()  { printf "\033[0;32m%s\033[0m\n" "$

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · plug.sh (reported line 3)May include surrounding context.

sh
#!/usr/bin/env bash
# Pulse Board — plug.sh
# Discovers cron jobs from system crontab and OpenClaw registry,
# presents a menu, and wires selected jobs into Pulse Board.
# No sudo. No root.
#
# Crontab writes: uses python3 subprocess to avoid shell escaping issues.
# Secrets env: if a secrets_env path is set in pulse.yaml, plug.sh wraps
# each wired cron command with "source <secrets_env> && <cmd>" so that the
# skill's runtime environment matches what you configured in install.sh.
# The secrets file is never read, parsed, or transmitted — only sourced
# in the cron shell context, exactly as if you had run it manually.

set -uo pipefail

SKILL_DIR="$(cd "$(dirname "${

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The changelog contains contradictory privacy claims: one entry says the raw log is 'never sent externally', while a later entry explicitly discloses that the raw pending log is included in prompts sent to the configured OpenClaw agent and may go off-host when using a remote/cloud provider. This is dangerous because operators may rely on the earlier statement and unknowingly expose sensitive operational logs, secrets, or incident data to third-party LLM infrastructure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill explicitly transmits operational logs to Telegram/Discord and may also send raw log content to an OpenClaw agent that could be backed by a remote LLM. Even though this is documented functionality, it creates a real data exfiltration/privacy risk if logs contain secrets, tokens, internal paths, or sensitive operational events.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
It may add `LLM_API_KEY=ollama` and `OPENCLAW_WORKSPACE=<path>` if missing.

### Network
- **Telegram:** `POST https://api.telegram.org/bot<token>/sendMessage`
- **Discord:** `POST <your webhook URL>`
- **OpenClaw agent:** `openclaw agent --agent <id> --message <prompt> --json` (local gateway call)
  ⚠️ The raw log is included in the prompt. If your agent uses a remote/cloud LLM, log content will be transmitted off-host. Use a local-only agent if log privacy is required.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script sources a shared secrets file even though its documented function is only to deliver an already-prepared message. Sourcing an external shell file imports all variables and executes any shell code in that file, unnecessarily expanding the trust boundary and exposing unrelated credentials to this process.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · deliver.sh (reported line 52)May include surrounding context.

sh
PAYLOAD="{\"chat_id\":\"$CHAT_ID\",\"text\":$TEXT,\"parse_mode\":\"Markdown\"}"
    [[ -n "$THREAD_ID" ]] && \
      PAYLOAD="{\"chat_id\":\"$CHAT_ID\",\"message_thread_id\":$THREAD_ID,\"text\":$TEXT,\"parse_mode\":\"Markdown\"}"
    curl -sf -X POST "https://api.telegram.org/bot${BOT_TOKEN}/sendMessage" \
      -H "Content-Type: application/json" -d "$PAYLOAD" --max-time 15 > /dev/null \
      && g "✓ Delivered to Telegram" || { r "Telegram delivery failed."; exit 1; }
    ;;

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · deliver.sh (reported line 52)May include surrounding context.

sh
PAYLOAD="{\"chat_id\":\"$CHAT_ID\",\"text\":$TEXT,\"parse_mode\":\"Markdown\"}"
    [[ -n "$THREAD_ID" ]] && \
      PAYLOAD="{\"chat_id\":\"$CHAT_ID\",\"message_thread_id\":$THREAD_ID,\"text\":$TEXT,\"parse_mode\":\"Markdown\"}"
    curl -sf -X POST "https://api.telegram.org/bot${BOT_TOKEN}/sendMessage" \
      -H "Content-Type: application/json" -d "$PAYLOAD" --max-time 15 > /dev/null \
      && g "✓ Delivered to Telegram" || { r "Telegram delivery failed."; exit 1; }
    ;;

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · deliver.sh (reported line 60)May include surrounding context.

sh
WEBHOOK="$(cfg_under 'discord' 'webhook_url')"
    [[ -z "$WEBHOOK" ]] && WEBHOOK="${PULSE_DISCORD_WEBHOOK_URL:-}"
    [[ -z "$WEBHOOK" ]] && { r "Discord: webhook_url not set."; exit 1; }
    curl -sf -X POST "$WEBHOOK" \
      -H "Content-Type: application/json" \
      -d "{\"content\":$TEXT}" --max-time 15 > /dev/null \
      && g "✓ Delivered to Discord" || { r "Discord delivery failed."; exit 1; }

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

In manual mode, the script accepts --skill/--cron/--cmd and immediately rewrites the user's crontab via wire_job with no interactive confirmation or dry-run. That creates a real safety issue because a mistyped or maliciously supplied command becomes persistent scheduled execution, which is especially sensitive in a tool whose core purpose is cron wiring.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 279)May include surrounding context.

sh
fi

# ── Remove cron entry ─────────────────────────────────────────────────────────
EXISTING_CRON="$(crontab -l 2>/dev/null || true)"

if echo "$EXISTING_CRON" | grep -q "pulse-board:$SKILL_SAFE"; then
  echo "$EXISTING_CRON" | grep -v "pulse-board:$SKILL_SAFE" | crontab -

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · plug.sh (reported line 152)May include surrounding context.

sh
fi

# ── Remove cron entry ─────────────────────────────────────────────────────────
EXISTING_CRON="$(crontab -l 2>/dev/null || true)"

if echo "$EXISTING_CRON" | grep -q "pulse-board:$SKILL_SAFE"; then
  echo "$EXISTING_CRON" | grep -v "pulse-board:$SKILL_SAFE" | crontab -

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · plug.sh (reported line 183)May include surrounding context.

sh
fi

# ── Remove cron entry ─────────────────────────────────────────────────────────
EXISTING_CRON="$(crontab -l 2>/dev/null || true)"

if echo "$EXISTING_CRON" | grep -q "pulse-board:$SKILL_SAFE"; then
  echo "$EXISTING_CRON" | grep -v "pulse-board:$SKILL_SAFE" | crontab -

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · unplug.sh (reported line 50)May include surrounding context.

sh
fi

# ── Remove cron entry ─────────────────────────────────────────────────────────
EXISTING_CRON="$(crontab -l 2>/dev/null || true)"

if echo "$EXISTING_CRON" | grep -q "pulse-board:$SKILL_SAFE"; then
  echo "$EXISTING_CRON" | grep -v "pulse-board:$SKILL_SAFE" | crontab -

Static analysis

No suspicious patterns detected.