T06 · System Persistence
- Location
SKILL.md:29- Finding
Persistent Autonomous Update Task Across Agent Sessions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill clearly says it will auto-update Clawdbot and all skills, but it sets up unattended recurring changes to the agent and installed skills without enough approval, pinning, or rollback controls.
Install only if you intentionally want unattended daily updates to Clawdbot and every installed skill. Prefer configuring it as notify-only or dry-run first, review proposed versions before applying them, keep a rollback path, and remove the cron job if you do not want recurring agent sessions changing your installation.
SKILL.md:29Persistent Autonomous Update Task Across Agent Sessions
SKILL.md:51Unpinned and Unattended Bulk Supply-Chain Updates
clawdhub update --all causes the agent environment to self-modify by replacing installed skills, potentially including the currently trusted behavior, from an external source. In context, this is more dangerous because it is part of an automated daily updater, so any compromised package, malicious skill update, or accidental breaking release can propagate persistently without manual review.
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")
# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"
The skill explicitly automates updating Clawdbot itself and all installed skills on a daily schedule, which can change system state, installed packages, and trusted code without an explicit user-facing warning about the risks of unattended updates. Even if sourced from legitimate registries, automatic bulk updates increase supply-chain and operational risk because a compromised package, breaking release, or privilege-sensitive package-manager action could be applied without timely human review.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"
## Step 2: Create the Update Script (Optional)
For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:
The cron-delivered instructions direct the agent to perform unattended package and skill updates plus clawdbot doctor --yes, which can change software state and apply migrations without an explicit warning, approval checkpoint, or rollback plan. This is dangerous because automatic updates modify trusted code and configuration on a schedule, increasing the risk of supply-chain compromise, breaking changes, or destructive migrations occurring without the user noticing beforehand.
This markdown example specifies daily updates at 4:00 AM in "America/Los_Angeles," which imposes a locale-specific setting in natural language. Under the policy, forcing a specific locale without user opt-in can be a violation unless the constraint is documented as justified or optional.
No suspicious patterns detected.