T06 · System Persistence
- Location
SKILL.md:287- Finding
Persistent Scheduled Webhook Execution Through Direct OpenClaw Cron Modification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches n8n administration, but it also tells agents to create persistent local scheduled jobs and use high-impact live operations without enough safeguards.
Review carefully before installing. Use this only with an n8n instance and API key you are comfortable letting the agent administer, prefer HTTPS or loopback-only HTTP, require explicit confirmation before create/update/delete/activate/deactivate/execute actions, avoid the direct OpenClaw jobs.json cron approach, and do not use the root Desktop bind-mount example on sensitive host data.
SKILL.md:287Persistent Scheduled Webhook Execution Through Direct OpenClaw Cron Modification
references/desktop-write.md:15Root n8n Container Receives Writable Access to the Host Desktop
scripts/n8n_tester.py:193Purported Dry Run Executes the Live Workflow and Its Side Effects
scripts/n8n_api.py:19Administrative n8n API Key Can Be Sent Over Unencrypted HTTP
references/node-templates.md:436Generic HTTP Template Sends the Entire Input Record to an External API
references/workflow-patterns.md:589Batch Notification Template Discloses User Email Addresses to Slack
The stated purpose is REST-based n8n workflow management, but the document also instructs performance analysis, reporting, local cron/job-file editing, and use of separate CLI/Python utilities. This mismatch weakens user consent and reviewability because the skill can induce actions outside the expected n8n-management scope, including local system changes and broader operational analysis.
The auto-activation criteria are extremely broad, including essentially any n8n-related request or automation-design discussion. Overbroad triggering raises the chance the skill is invoked in contexts where the user only wanted advice, causing unintended access to credentials, workflow mutation, execution, or deletion.
Referenced artifact was not completely inspected
python3 scripts/n8n_api.py list-workflows --active true --pretty
Referenced artifact was not completely inspected
python3 scripts/n8n_api.py list-workflows --active true --pretty
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
DELETE /workflows/{id}
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
DELETE /executions/{id}
The skill declares access to environment variables and documents file/network operations, but does not constrain its tool scope with explicit permissions or allowed-tools. In practice this can let an agent apply broader capabilities than users expect, including reading secrets like N8N_API_KEY and making outbound or local-file modifications without a clearly bounded contract.
The skill description is written to operate in Chinese and does not indicate that the user may choose another language or locale. Per the policy, forcing a specific language without opt-in is a natural-language policy issue unless the locale constraint is explicitly justified.
The skill documents destructive operations like delete, activate/deactivate, execute, and local file modification without prominent risk warnings or confirmation requirements. In an agent setting, missing safeguards make accidental service disruption, workflow loss, or persistent local changes more likely.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
| 详情 | GET | /executions/{id} |
| 重试 | POST | /executions/{id}/retry |
# 列出所有工作流
The skill directs the agent to edit a local OpenClaw cron jobs.json file to trigger webhooks, which extends from remote n8n administration into local persistence and scheduled execution. This is dangerous because it creates durable system behavior outside the declared REST API boundary and could be used to establish unauthorized recurring network activity.
The document explicitly instructs writing files to the user's Windows Desktop, which is a user-owned, high-visibility location, without any warning, confirmation, or guidance about the risks of modifying local files. In the context of an agent skill that can design and manage workflows, this lowers the barrier to creating automations that overwrite or drop files onto the host desktop, increasing the chance of unintended data modification or abuse.
This markdown file includes ready-to-copy templates for Slack, email, Telegram, WeChat Work, DingTalk, and generic HTTP Request nodes that send {{$json...}} data to external services. The surrounding documentation explains configuration details but does not warn users that workflow data may be transmitted to third parties or that credentials and recipient targets should be reviewed before use.
The document provides templates for MySQL/PostgreSQL/Redis/MongoDB and file read/write operations, including references to update/delete-capable database nodes and filesystem access. While these are example templates, the markdown does not warn that such nodes can alter stored data or access local files and should be used only with reviewed paths, queries, and permissions.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -s -H "X-N8N-API-KEY: $N8N_API_KEY" \
"$N8N_BASE_URL/api/v1/workflows?active=true&limit=50"
The document provides ready-to-use workflow examples that perform outbound HTTP requests, send Slack messages, read/write databases, and instruct activation of workflows, but it does not consistently warn users about data egress, side effects, credential scope, or production impact. In an agent skill context, these examples can be operationalized directly, increasing the chance that sensitive data is transmitted or systems are modified without explicit user awareness or confirmation.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
{
"parameters": {
"url": "https://api.example.com/orders?updated_after={{ $now.minus({days: 1}).toISO() }}",
"method": "GET",
"options": { "response": { "response": { "responseFormat": "json" } } }
},
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
{
"parameters": {
"url": "https://api.example.com/orders?updated_after={{ $now.minus({days: 1}).toISO() }}",
"method": "GET",
"options": { "response": { "response": { "responseFormat": "json" } } }
},
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
{
"parameters": {
"url": "https://api.example.com/orders?updated_after={{ $now.minus({days: 1}).toISO() }}",
"method": "GET",
"options": { "response": { "response": { "responseFormat": "json" } } }
},
The module docstring explicitly states it manages "workflows, executions, and credentials via n8n REST API," which expands the apparent scope beyond the manifest's description of a workflow assistant. Credential management is materially more sensitive than ordinary workflow CRUD and is not mentioned in the stated purpose.
The code creates workflows via a POST request to the n8n API, which changes remote system state, but this path has no confirmation prompt or user-facing disclosure at the call site. While the method docstring names the action, the CLI flow provides no explicit warning before creating resources from a file or template.
These methods activate or deactivate workflows in the remote n8n environment, which can materially affect automation behavior, but there is no confirmation prompt, logging, or user-facing warning when the CLI invokes them. The docstrings are internal developer documentation and do not provide runtime disclosure to the user.
The execute_workflow method POSTs workflow input data to the n8n API, which may transmit user or system data, but there is no visible disclosure or warning in the code path that this data will be sent over the network. The CLI accepts arbitrary JSON via --data and immediately transmits it.
The dry-run path forwards user-supplied test data directly to the remote n8n service via execute_workflow without any explicit user-facing warning, confirmation, or redaction step. In a workflow-testing tool, operators may assume local validation semantics, but this function can transmit secrets, personal data, or internal payloads to a live service and potentially trigger downstream workflow actions during testing.
The manifest frames the skill as an n8n operator for workflow lifecycle management. The WeChat API limits and access-token handling guidance describe domain-specific third-party API behavior, which is not necessary to justify the core capability of managing n8n workflows and suggests unrelated operational specialization.
No suspicious patterns detected.