Back to skill

Security audit

Cron Helper

Security checks for vulnerabilities and agentic risk

Overview

This skill is aimed at OpenClaw cron management, but its repair tools can alter persistent scheduled-job configuration with unsafe temporary files and imperfect validation.

Review carefully before installing. This skill is not evidence of exfiltration or intentional harm, but it can modify persistent OpenClaw cron jobs. Prefer running the validators read-only first, avoid the bulk repair scripts on important configs until temporary-file and validation issues are fixed, keep backups, and confirm timezone, delivery targets, and diffs before replacing jobs.json.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fix-all.sh:49
Finding

Predictable Temporary Files Allow Symlink-Based File Clobbering

Content
View full analysis
/tmp/openclaw_cron_fixed.json FIXED_PEER=$(cat /tmp/openclaw_cron_fixed.json | jq '[.jobs[] | select(.delivery.peer != null)] | length') if [ "$FIXED_PEER" -eq 0 ]; then mv /tmp/openclaw_cron_fixed.json "$JOBS_FILE" fi ``` From `scripts/fix-all-safe.sh`: ```bash TEMP_FILE="/tmp/openclaw_cron_fixed_$$.json" WORK_FILE="$TEMP_FILE" cp "$JOBS_FILE" "$WORK_FILE" jq '( .jobs | map( if .delivery.peer != null then .delivery.to = ("chat:" + .delivery.peer.id) | del(.delivery.peer) | . else . end ) ) | {jobs: .}' "$WORK_FILE" > "$TEMP_FILE.tmp" if [ -s "$TEMP_FILE.tmp" ]; then mv "$TEMP_FILE.tmp" "$WORK_FILE" fi ``` From `scripts/fix-all-with-validation.sh`: ```bash TEMP_FILE="/tmp/openclaw_cron_fixed_$$.json" ... if "$VALIDATE_SCRIPT" "$WORK_FILE" 2>&1 | tee /tmp/validate_output_$$.txt; then ``` The documentation also recommends a fixed path: ```bash jq '...' ~/.openclaw/cron/jobs.json > /tmp/jobs_pending.json ~/.openclaw/skills/cron-helper/scripts/validate-jobs-syntax-v2.sh /tmp/jobs_pending.json mv /tmp/jobs_pending.json ~/.openclaw/cron/jobs.json ``` ### Technical Analysis The scripts create working and output files in the shared `/tmp` directory using fixed names or names based only on the process ID. They do not use `mktemp`, exclusive creation, a private temporary directory, or symlink checks. Shell output redirec ...[truncated 2030 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fix-all-safe.sh:55
Finding

Repair Filters Silently Delete Unrelated Top-Level Configuration

Content
View full analysis
"$TEMP_FILE.tmp" ``` The same reconstruction pattern is used for schedule repair: ```bash jq '( .jobs | map( if .schedule.cronExpression != null then .schedule.expr = .schedule.cronExpression | del(.schedule.cronExpression) | . else . end ) ) | {jobs: .}' "$WORK_FILE" > "$TEMP_FILE.tmp" ``` It is also used for delivery-mode repair: ```bash jq '( .jobs | map( if .delivery.mode == "none" then .delivery.mode = "announce" | . else . end ) ) | {jobs: .}' "$WORK_FILE" > "$TEMP_FILE.tmp" ``` Equivalent filters appear in `scripts/fix-all-with-validation.sh`. ### Technical Analysis Each filter first extracts `.jobs`, maps over the array, and then reconstructs the complete document as: ```jq {jobs: .} ``` This reconstruction preserves the job array but discards every other top-level property from the original JSON document. For example, fields such as schema versions, defaults, migration metadata, ownership information, or future OpenClaw settings would be removed. This behavior conflicts with the scripts’ “safe” designation and with the documented requirement to modify only the intended fields. The validator does not detect the loss because it validates only the resulting job structure and has no baseline comparison for unrelated data. ### Attack Path 1. A valid `jobs.json` contains `.jobs` and one or more additional top-level properties. 2. At least one job cont ...[truncated 987 chars]
Remediation
View remediation
"$OUTPUT_FILE" ``` Apply the same pattern to the schedule and delivery-mode repairs. Additional hardening should include: 1. Compare all non-`.jobs` top-level fields before and after transformation: ```bash jq -S 'del(.jobs)' "$WORK_FILE" > "$TEMP_DIR/root-before.json" jq -S 'del(.jobs)' "$OUTPUT_FILE" > "$TEMP_DIR/root-after.json" cmp -s "$TEMP_DIR/root-before.json" "$TEMP_DIR/root-after.json" || exit 1 ``` 2. Verify that the number and IDs of jobs remain unchanged unless the requested operation explicitly requires otherwise. 3. Add regression tests using input documents with additional top-level fields. 4. Perform a final diff and display the exact changed paths before overwriting the live file. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/validate-jobs-syntax.sh:87
Finding

Validator Returns Success for Structurally Incomplete Cron Configurations

Content
View full analysis
/dev/null || echo "0") if [ "$count" -gt 0 ]; then echo -e "${YELLOW}⚠️ $count 个任务缺少 '${field}'${NC}" WARNINGS=$((WARNINGS + 1)) fi } check_field "id" check_field "name" check_field "enabled" check_field "schedule" check_field "payload" ``` A warning-only result returns success: ```bash if [ $ERRORS -eq 0 ] && [ $WARNINGS -eq 0 ]; then exit 0 elif [ $ERRORS -eq 0 ]; then echo -e "${YELLOW}⚠️ 发现 $WARNINGS 个警告(非致命)${NC}" exit 0 else exit 1 fi ``` The repair script treats that exit status as authorization to install the file: ```bash if "$VALIDATE_SCRIPT" "$WORK_FILE" 2>&1 | tee /tmp/validate_output_$$.txt; then echo -e "${COLOR_GREEN}✅ 语法校验通过!${COLOR_NC}" else rm -f "$TEMP_FILE" "$TEMP_FILE.tmp" "/tmp/validate_output_$$.txt" exit 1 fi ... if [ $TOTAL_FIXES -gt 0 ]; then cp "$WORK_FILE" "$JOBS_FILE" fi ``` However, the documented validation table states that required fields, delivery fields, payload kind, cron expression validity, and timeout requirements are blocking checks. ### Technical Analysis The validator’s implementation does not match its documented security guarantees. Missing fields such as `id`, `name`, `enabled`, `schedule`, and `payload` increment only `WARNINGS`. When no separately classified error exists, the validator exits with status zero. The validation-enabled repair script therefore accepts and installs the fil ...[truncated 2140 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a broad skill for configuring, diagnosing, and fixing OpenClaw cron jobs. The provided code, however, is a narrowly scoped validation utility: it reads a target jobs.json file, uses jq to verify JSON syntax and schema-like constraints, reports warnings/errors, and exits with status codes. It does not modify configurations, repair issues, schedule jobs, inspect runtime behavior, or troubleshoot timing/heartbeat problems. While the code is related to cron jobs, its primary purpose is substantially narrower than the declared functionality, so this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code’s actual function is narrowly limited to validating an OpenClaw cron/jobs JSON file. It reads a target file (or the current jobs.json), runs jq-based checks, reports warnings/errors, and exits. It does not configure jobs, repair them, schedule tasks, inspect runtime cron state, diagnose execution/timing failures, or otherwise manage heartbeat/time-based automation. While syntax validation can be considered a supporting diagnostic function, the declared purpose claims substantially broader capabilities—configure, diagnose, and fix cron jobs—than what this code chunk actually implements. Therefore this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/fix-all.sh (reported line 62)May include surrounding context.

sh
echo -e "${COLOR_GREEN}✅ 成功修复 $FIX_PEER 个任务${COLOR_NC}"
  else
    echo -e "${COLOR_RED}❌ 修复失败,请手动检查${COLOR_NC}"
    rm /tmp/openclaw_cron_fixed.json
  fi
else
  echo -e "${COLOR_GREEN}✅ 无需修复${COLOR_NC}"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/fix-all.sh (reported line 94)May include surrounding context.

sh
echo -e "${COLOR_GREEN}✅ 成功修复 $FIX_EXPR 个任务${COLOR_NC}"
  else
    echo -e "${COLOR_RED}❌ 修复失败,请手动检查${COLOR_NC}"
    rm /tmp/openclaw_cron_fixed2.json
  fi
else
  echo -e "${COLOR_GREEN}✅ 无需修复${COLOR_NC}"

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation criteria are very broad, causing this skill to trigger for many generic time-automation discussions. Over-broad activation can route users into a high-authority workflow that includes instructions for editing persistent cron configuration files, increasing the chance of unintended or unsafe configuration changes in unrelated contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document mandates a fixed timezone (Asia/Shanghai) without checking user environment or intent. In a cron-management skill, forcing the wrong timezone can cause jobs to run at unintended times, potentially missing monitoring windows, triggering actions during off-hours, or executing business workflows at the wrong moment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/troubleshooting.md (reported line 40)May include surrounding context.

md
This is a **stateless prompt problem** — see SKILL.md "Statefulness Design Rules".

The prompt must include:
- A state file to read/write
- A cursor or checkpoint mechanism
- Explicit instructions for what to do with new vs already-processed data

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/troubleshooting.md (reported line 74)May include surrounding context.

md
# 4. Validate temp file
~/.openclaw/skills/cron-helper/scripts/validate-jobs-syntax-v2.sh /tmp/jobs_pending.json

# 5. Atomic write
mv /tmp/jobs_pending.json ~/.openclaw/cron/jobs.json

# 6. Post-verify

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's comments and terminal messages are consistently written in Chinese, which enforces a specific language for all users. Under the stated policy, forcing a locale or language without opt-in is a natural-language policy violation unless the constraint is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script presents its description, usage text, errors, and status messages entirely in Chinese, which imposes a specific language on users. The policy allows locale constraints only when they are explicitly documented and justified or when users are offered a language choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This code invokes openclaw cron runs and prints returned status and error information to the terminal. While the script is diagnostic in nature, there is no explicit warning or disclosure that it will surface recent run details and error messages, which may contain sensitive operational information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's comments, usage text, status messages, and error output are all written in Chinese, including the user-facing CLI output. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.