T06 · System Persistence
- Location
SKILL.md:106- Finding
Unbounded Recurring Cross-Session Execution Through Cron
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is purpose-aligned but sets up recurring background optimization that writes files and spawns subagents without enough bounds or cleanup controls.
Review this before installing if you are comfortable with an automated cron job that keeps running every five minutes, edits sandbox files, logs results, and forwards full guidance and test data to subagents. Use only a new dedicated sandbox with non-sensitive content, avoid absolute paths, inspect the cron entry before enabling it, and make sure you know exactly how to stop and remove the job.
SKILL.md:106Unbounded Recurring Cross-Session Execution Through Cron
SKILL.md:190Untrusted Guidance and Fixture Content Is Delegated to a Subagent Without Isolation
SKILL.md:40Arbitrary Sandbox Paths Permit Unsafe File Creation and Overwrite
The skill directs the agent to set up cron as part of normal operation without an explicit warning that this creates a persistent background scheduled task. Persistent automation is more dangerous than a one-time action because it can continue executing repeatedly, consume resources, modify data over time, or become difficult for the user to notice and remove if created unintentionally.
The description highlights optimization convenience but does not clearly warn that the skill performs repeated automated file modifications and sets up cron-triggered execution. Because this skill continuously edits guidance and may copy external scripts into a sandbox, the lack of upfront warnings can mislead users about persistence, write activity, and operational risk.
The README advertises a bare /autoagent trigger with no scope constraints, even though the skill can create sandboxes, copy files, and schedule recurring optimization runs. A generic invocation increases the chance of accidental activation and makes it easier for users or downstream agents to start a powerful workflow without first narrowing target paths, schedules, or modification boundaries.
The skill creates directories at user-specified paths, copies files, edits working guidance, and schedules recurring cron execution, but its description does not prominently warn about these persistent side effects. Users may invoke it expecting a one-shot advisory skill and unintentionally authorize ongoing file writes and repeated automated actions.
The skill explicitly expands its behavior from prompt/guidance optimization into locating, reading, and evaluating arbitrary external scripts or tools referenced by the user. That broadens the trust boundary and can lead the agent to inspect or reason about unrelated codebases, proprietary tooling, or sensitive local artifacts without a clear scope limitation, increasing the chance of unintended data exposure or unsafe recommendations.
The skill goes beyond recommending prompt improvements and suggests modifying open-source scripts to improve functionality. This creates scope creep from text optimization into code-change guidance, which can drive the agent to propose or facilitate changes to executable logic that the user did not originally intend to entrust to this skill.
The iteration phase instructs the agent to send the full contents of current-guidance.md and inline test cases to a spawned subagent, but does not warn users that potentially sensitive prompts, fixtures, or embedded data will be propagated to another execution context. This can expose confidential instructions, proprietary evaluation data, or secrets accidentally stored in guidance/test files.
The skill explicitly instructs the agent to overwrite current-guidance.md as part of its loop without requiring user confirmation or a dry-run step. Even if intended behavior is optimization, autonomous file modification can silently alter important guidance and create integrity and auditability risks, especially when the edits are derived from model-generated judgments.
The document specifies creation of a cron job that runs every 5 minutes, but it does not mention obtaining explicit user consent, notifying the user about persistent background execution, or explaining how to inspect and remove the job. Persistent scheduled execution increases risk because it can continue consuming resources, modifying files, or invoking subagents after the initial interaction has ended.
The setup flow instructs the agent to create directories and multiple files on the user's filesystem, including allowing absolute paths, but does not require an explicit warning or a final confirmation immediately before making those changes. This creates a real risk of unintended writes in sensitive locations, especially because users may not understand the path resolution behavior or may provide ambiguous input.
The skill instructs the agent to append entries to scores.md persistently on each run without notifying the user or obtaining consent. While lower impact than overwriting guidance, silent log growth can cause unwanted state changes, pollute project history, and make automated experimentation harder to review or roll back.
No suspicious patterns detected.