T06 · System Persistence
- Location
SKILL.md:17- Finding
Persistent Scheduled Agent Execution Through Cron Jobs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is purpose-aligned but needs review because it sets up recurring agent jobs that broadly read installed skill files and write persistent registry, guide, README, and notification outputs with insufficient containment.
Install only if you intentionally want an administrator-level autonomous Skill inventory service. Before using the cron setup, restrict the scanned directories, run the scheduled agent with least privilege, pin or verify the approved SKILL.md hash before each scheduled run, add explicit rules that scanned Skill contents are untrusted data, and fix the guardian-check.sh path containment logic. Expect it to overwrite generated guides and README entries and to send change notifications when configured.
SKILL.md:17Persistent Scheduled Agent Execution Through Cron Jobs
SKILL.md:146Indirect Prompt Injection Through Untrusted Skill Documents
guardian-check.sh:38Path Whitelist Bypass and Symlink Time-of-Check/Time-of-Use Race
The supplied code chunk is much narrower than the declared description. It implements only one supporting sub-function: hash-based change detection for already-registered skill files, plus path-whitelist safety checks. It does not scan all workspaces dynamically, does not discover new skills, does not detect functional overlap, does not write guides or README files, and does not perform notification logic. While the description mentions a V2 hash change detector and path whitelist hardening that align with this script, the overall declared purpose describes a broader lifecycle-management skill whose main capabilities are not present in this code chunk. Therefore the description does not accurately represent what this specific code actually does.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
> "name": "skill-guardian-daily-scan",
> "schedule": {"kind":"cron","expr":"0 6 * * *","tz":"Asia/Shanghai"},
> "sessionTarget": "isolated",
> "payload": {"kind":"agentTurn","message":"请读取 ~/.openclaw/workspace/skills/skill-lifecycle-guardian/SKILL.md,严格按「工作流程」章节执行每日扫描。","timeoutSeconds":300},
> "delivery": {"mode":"announce"}
> }'
> ```
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
> "name": "skill-guardian-daily-scan",
> "schedule": {"kind":"cron","expr":"0 6 * * *","tz":"Asia/Shanghai"},
> "sessionTarget": "isolated",
> "payload": {"kind":"agentTurn","message":"请读取 ~/.openclaw/workspace/skills/skill-lifecycle-guardian/SKILL.md,严格按「工作流程」章节执行每日扫描。","timeoutSeconds":300},
> "delivery": {"mode":"announce"}
> }'
> ```
The instruction '中文输出' requires all output to be in Chinese, which is a language policy constraint expressed in natural language. The file does not provide user opt-in, a language selection mechanism, or a documented justification that this skill is region-specific.
L113-L118声明“第零步:变更检测”仅在每日定时扫描时执行,手动触发跳过;但上文自动触发说明和 cron 配置明确将“每 3 小时变更检测”也用于检测是否有变更(L036-L043、L072-L073)。这不是信息缺失,而是文档内对同一流程适用范围的直接矛盾,可能导致执行代理错误跳过或重复执行检测逻辑。
No suspicious patterns detected.