T06 · System Persistence
- Location
references/agent-guide.md:75- Finding
Unattended Scheduled Updates Create Persistent Cross-Session Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is transparent about setting up daily updates, but it can automatically replace Clawdbot and every installed skill without fresh approval.
Install only if you are comfortable allowing a daily job to modify Clawdbot and every installed skill automatically. Prefer dry-run notifications, explicit approval before installation, pinned or verified versions, backups, and a clear rollback and disable process before enabling this in a sensitive environment.
references/agent-guide.md:75Unattended Scheduled Updates Create Persistent Cross-Session Execution
SKILL.md:54Unpinned Automatic Updates Permit Supply-Chain Code Execution
This is a real self-modification risk: the skill instructs the system to run clawdhub update --all, which changes installed skills automatically, and also updates Clawdbot itself. In an auto-update cron context, this is more dangerous because it repeatedly imports remote code changes without human review, amplifying supply-chain compromise and persistence risks.
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")
# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"
The guide instructs the agent to enable unattended updates of both the core tool and all installed skills, but it does not include a clear user-facing warning that this grants remote packages ongoing authority to change code and behavior automatically. In this context, that increases supply-chain risk and can introduce breaking or malicious changes without fresh user review.
The guide recommends creating a persistent helper script in ~/.clawdbot/scripts and scheduling it for recurring use, which establishes durable behavior beyond the immediate session. In a security context, persistence increases the blast radius of any unsafe update logic because the behavior continues automatically and may be overlooked after initial setup.
bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"
## Step 2: Create the Update Script (Optional)
For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:
The optional helper script creates a persistent log file under ~/.clawdbot/logs without clearly disclosing that ongoing artifacts will be written to disk. While not severe by itself, silent persistence can expose update history, package names, errors, and potentially sensitive command output to other local users or future processes depending on filesystem permissions.
The setup confirmation example states that daily updates will run at "4:00 AM (America/Los_Angeles)", which imposes a specific locale/time zone in natural-language output. Because the file does not indicate that this is user-configurable or selected by user preference within the example, it can conflict with language/locale policy expectations.
No suspicious patterns detected.