T06 · System Persistence
- Location
SKILL.md:22- Finding
Persistent Recurring Agent and Script Execution Through a Scheduled Cron Job
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This watchdog is mostly purpose-aligned, but it installs persistent recurring automation that can repeatedly execute a workspace script and restart the OpenClaw gateway without strong safeguards.
Install only if you explicitly want a persistent watchdog that runs every five minutes and can restart the OpenClaw gateway. Review and preferably harden the script path, cron job, restart thresholds, process matching, and log path before enabling it; also verify you know how to disable or remove the cron job.
SKILL.md:22Persistent Recurring Agent and Script Execution Through a Scheduled Cron Job
scripts/watchdog.py:25Incorrect Cross-Platform Paths Cause Fail-Open Disk Monitoring and Misplaced Logs
scripts/watchdog.py:104Overbroad Process Matching Can Trigger Repeated Unnecessary Gateway Restarts
scripts/watchdog.py:84Advertised Zombie-Session Monitoring and Auto-Healing Are Not Implemented
The code largely matches the watchdog/auto-healer description for gateway health, memory, disk checks, logging, and gateway restart. However, a material part of the declared behavior is missing: session health checking is effectively a stub that always returns no zombies, and no session-kill action exists. Also, the script does not itself run every 5 minutes; it is intended to be invoked by cron or CLI. Because the declared description explicitly includes zombie session monitoring/cleanup and a concrete periodic cadence, but the supplied code does not implement those behaviors, this is a description-to-behavior mismatch.
The skill instructs the agent to copy files into a persistent workspace and create a recurring cron-driven agentTurn that executes a Python script, but it declares no explicit tool scope or permissions. That makes powerful file-write and shell-like capabilities implicit rather than bounded, increasing the chance of overreach, unsafe execution, or unauthorized persistence.
The skill promotes a 'zero manual intervention' watchdog that runs every five minutes and performs auto-healing, including restart actions, without prominently warning users about ongoing autonomous system changes. This is dangerous because users may enable persistence and recurring restarts without understanding that the agent will continue making operational changes after the initial setup.
The trigger list includes broad, common phrases such as 'watchdog', 'guardian', 'health monitor', and 'memory monitor', making accidental or unintended invocation plausible. In this skill’s context, unintended invocation is risky because activation can lead to persistent scheduling and automated restart behavior that changes system state.
The skill explicitly instructs creation of a recurring isolated agentTurn job that repeatedly executes a workspace script every five minutes. Persistent autonomous execution materially increases risk because any flaw, later modification, or abuse of the referenced script can be re-triggered indefinitely, and the announce-only reporting pattern may hide normal activity except on error.
(Use cp -r / copy; adjust the destination as needed. Keep the guardian/ folder in workspace.)
cron tool to create a recurring agentTurn job:
{
"schedule": { "kind": "every", "everyMs": 300000 },
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run(cmd: list[str], timeout: int = 15) -> tuple[int, str, str]:
try:
p = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout, shell=False)
return p.returncode, p.stdout.strip(), p.stderr.strip()
except subprocess.TimeoutExpired:
return -1, "", f"TIMEOUT after {timeout}s"
No suspicious patterns detected.