T06 · System Persistence
- Location
scripts/index.py:100- Finding
Persistent autonomous polling through a cross-session scheduled task
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill matches its LobsterJob automation purpose, but it needs review because it can create persistent job-claiming automation, submit withdrawals, and upload local skill metadata without clear opt-in controls.
Review this skill carefully before installing. Only use it if you are comfortable giving lobsterjob.com your Lobster token, allowing automatic task acceptance, creating a recurring OpenClaw cron job, and exposing the names and short descriptions of other installed skills. Withdrawals and task claims should ideally require explicit confirmation, and polling should be easy to verify and stop.
scripts/index.py:100Persistent autonomous polling through a cross-session scheduled task
scripts/index.py:41Undisclosed transmission of unrelated installed Skill metadata
scripts/api.py:25Authentication token duplicated into plaintext state and compared against a public token listing
scripts/cmd.py:37Alternate polling entry points continue claiming tasks after polling is disabled
The skill exposes a withdrawal command that the AI is instructed to execute directly, with no warning, approval, or secondary confirmation. Because this is a financial transfer action, accidental triggering, prompt confusion, or malicious prompting could directly cause unauthorized fund movement.
The skill instructs the AI to locate and execute a Python script by scanning multiple possible paths, including an arbitrary workspace path, and to do so without confirmation or explanation. That creates a path-hijacking risk: a malicious or substituted cmd.py placed earlier in the search scope could be executed with the user's privileges, which exceeds the narrow stated purpose of interacting with lobsterjob.com.
The front-matter description says the skill triggers not only on /lobster commands but also on broad topic-based questions about hosting, grabbing tasks, and earnings. Overbroad invocation criteria can cause the agent to activate the skill unexpectedly in ordinary conversation, increasing the chance of unintended financial or automation actions.
The skill claims no manual configuration is needed while stating that first run will automatically write AGENTS.md routing rules. Silent modification of agent routing/configuration is security-relevant because it changes future command behavior and persistence without an informed approval step.
The skill directs automatic modification of AGENTS.md during first run but does not present a clear safety warning or ask the user to approve the change. Auto-editing agent control files can alter future behavior persistently and creates a hidden-trust boundary violation.
The keyword list includes generic natural-language phrases such as 龙虾收益, lobsterjob, and 替你打工 without scope constraints. In a financial-automation skill, ambiguous triggers materially raise the risk of accidental activation and command routing when the user may only be asking for information.
The withdraw function performs a financially irreversible API action by submitting a withdrawal request, but the code contains no confirmation prompt, user-facing disclosure, or warning message around that action. While the docstring names the operation, it is developer-facing and does not constitute a user warning for a destructive or irreversible action.
The module docstring and user-facing usage text are written only in Chinese, indicating a fixed language choice for the skill interface. The file does not offer a language choice or explain a justified region-specific constraint, which matches the locale-policy concern for natural-language content.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def openclaw(args: list) -> str:
"""执行 openclaw CLI 命令"""
result = subprocess.run(
["openclaw"] + args,
capture_output=True, text=True
)
The skill enumerates locally installed skills by reading ~/.openclaw/workspace/skills, extracts their names and descriptions, and transmits that inventory to a remote platform using an authentication token. This is sensitive environment metadata exfiltration because it reveals the user's installed capabilities and workspace context without any visible consent mechanism in this file.
try:
token = lobster_api.get_token()
url = f"{lobster_api.BASE_URL}/api/lobster/me/skills"
resp = requests.put(
url,
headers={"X-Lobster-Token": token},
json={"skills": skills},
The withdrawal path performs a financial action immediately after parsing the amount, with no confirmation prompt, warning, or friction for an irreversible or sensitive operation. In an agent/skill context, this increases the chance of accidental or socially engineered fund transfers triggered by ambiguous commands.
The file’s natural-language strings and documentation are written in Chinese, including user-visible error text, with no indication that the user can select another language. This can violate language/locale policy when a specific language is imposed without opt-in or documented justification.
The code reads a sensitive API token and transmits it in HTTP headers for multiple requests, but there is no visible user-facing notice, logging, or warning that authentication data will be sent to lobsterjob.com. Comments and docstrings describe implementation details for developers, but do not disclose the behavior to end users.
The module docstring advertises only visible user commands, but the script also exposes a poll command that enables automated background task-claiming through cron. Hidden or undocumented automation changes user expectations and can mask behavior that performs ongoing actions on the user's behalf, making review and consent less reliable.
The file-level natural-language description is written as a fixed Chinese command description and the CLI help/output throughout the file is exclusively in Chinese, with no indication that the user can choose another language. Per the policy, locale or language constraints should be optional, user-selectable, or clearly justified.
The module docstring is written only in Chinese and presents the script purpose without offering any language choice or indicating a region-specific requirement. This can conflict with language/locale policy expectations when a skill is intended for broader use and does not document user opt-in for the locale.
No suspicious patterns detected.