T06 · System Persistence
- Location
SKILL.md:27- Finding
Persistent Unattended Update Execution Through a Scheduled Cron Job
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s update purpose is clear, but it sets up unattended daily jobs that can change Clawdbot and every installed skill without a fresh approval step.
Install only if you intentionally want Clawdbot to update itself and all installed skills automatically. Prefer changing it to check-only or dry-run mode, review exact versions before installing, limit updates to trusted skills, and confirm the cron timezone and removal path before enabling it.
SKILL.md:27Persistent Unattended Update Execution Through a Scheduled Cron Job
SKILL.md:51Unpinned Automatic Installation of Mutable Core and Skill Updates
clawdhub update --all performs self-modification by replacing installed skills from an external source, potentially altering the agent's capabilities and trust boundary on a recurring basis. In the context of a cron-driven auto-updater, this amplifies supply-chain risk because a compromised or malicious skill update would be fetched and activated automatically.
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")
# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"
The skill instructs the system to automatically perform package-manager and skill updates on a daily schedule, which can modify installed software and write to disk without prominently warning the user about those changes. Auto-updating expands supply-chain risk and can introduce breaking changes or malicious upstream updates with no explicit confirmation step in the described workflow.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"
## Step 2: Create the Update Script (Optional)
For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:
The guide instructs the agent to schedule unattended daily execution of package and migration commands that change the local installation and all installed skills. Because these updates occur automatically and without approval gates, rollback guidance, or pinning, a bad upstream release or compromised package/feed could silently modify the agent environment and affect future behavior.
The example setup command hard-codes the timezone to America/Los_Angeles, which may cause the cron job to run at an unexpected local time for many users. While not directly a code-execution issue, unexpected execution timing makes unattended automatic updates less predictable and can increase operational risk.
No suspicious patterns detected.