T06 · System Persistence
- Location
SKILL.md:12- Finding
Recurring Background Sub-Agent Creates Cross-Session Persistence
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12–24
Vulnerability Type: Scheduled cross-session background execution
Risk Level: HighComplete Code Snippet:
markdown ## Initialization Upon first run, the primary agent must **spawn a specialized sub-agent** named `reddit-geo-marketing-agent`. This sub-agent inherits the tools and configuration below to operate independently of the main conversation thread. ## Configuration - **Brand Name**: [Your Brand Name] - **Website**: [Your URL] - **Keywords**: [keyword1, keyword2, "best alternative to X"] - **Default Schedule**: `0 9,18 * * *` (9:00 AM and 6:00 PM Daily) - **User Modification**: Users can update the schedule by saying "Change my Reddit report time to [Time/Cron]." ## Workflow & Sub-Agent Instructions ### 1. The Cron Routine (Scheduled Execution) - **Background Run**: The `reddit-geo-marketing-agent` is initialized via `sessions_spawn` to run in the background. - **Pre-Trigger Action**: The sub-agent must begin its search/drafting process **30 minutes prior** to the scheduled reporting time to ensure the digest is ready. - **Reporting**: At 9:00 AM and 6:00 PM, the sub-agent will deliver a summary of findings to the primary chat session using the `announce` delivery mode.Technical Analysis
The skill mandates spawning an independently operating sub-agent on first run and assigns it a recurring cron schedule. This creates an execution mechanism that survives the initiating interaction and activates twice daily without requiring a fresh invocation.
The persistent agent inherits tools including web search, web fetching, browser access, and sub-agent spawning. Its documented workflow can therefore repeatedly access external content and prepare browser-based posting activity. The requirement for a separate approval before posting reduces the likelihood of unauthorized publication, but it does not eliminate the scheduled persi ...[truncated 1348 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not spawn a background agent or create a recurring schedule automatically on first run.
- Default to a one-shot workflow that executes only in direct response to a user request.
- Before creating a scheduled task, obtain explicit and informed confirmation that displays:
- The exact cron expression and effective time zone.
- The sub-agent identity and execution frequency.
- Every tool and external service available to the job.
- The data sent to external websites.
- Instructions for inspecting, pausing, and permanently deleting the job.
- Use a separate, least-privileged tool profile for scheduled runs. Exclude browser posting and sub-agent spawning unless they are essential.
- Keep browser submission disabled during background runs and require per-action user authorization immediately before every post.
- Add expiration and execution-count limits so schedules do not remain active indefinitely.
- Record auditable creation, execution, configuration-change, and deletion events for the scheduled job.
- Require confirmation before schedule changes and validate cron input against safe frequency limits.
