T06 · System Persistence
- Location
SKILL.md:57- Finding
Persistent Hidden Execution Through Task Scheduler and systemd
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 57-76
Vulnerability Type: Cross-session execution persistence
Risk Level: HighThe Skill directs users to configure either a recurring Windows Task Scheduler job that launches hidden PowerShell with execution-policy bypass or a Linux systemd service configured to restart continuously.
Complete vulnerable code:
vbs ' guardian-silent.vbs — zero flash process monitor Set oShell = CreateObject("WScript.Shell") oShell.Run "powershell.exe -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -File ""C:\path\to\guardian.ps1""", 0, Truetext Register as Task Scheduler job running every 1-5 minutes.bash # /etc/systemd/system/openclaw-watchdog.service [Service] ExecStart=/usr/bin/node /path/to/guardian.js Restart=always RestartSec=60Technical Analysis
Windows Task Scheduler and Linux systemd are operating-system persistence mechanisms that survive the original Skill invocation and user session. The Windows configuration is particularly risky because it combines frequent scheduled execution with
-WindowStyle Hiddenand-ExecutionPolicy Bypass, reducing execution visibility and bypassing PowerShell's configured script-execution policy.The systemd example establishes similar persistence by executing
guardian.jsas a service and settingRestart=always. The actualguardian.ps1andguardian.jsimplementations are not included in the reviewed project, so their commands, input validation, privilege requirements, and integrity cannot be audited. Consequently, the persistent mechanisms would repeatedly execute code whose security properties are unknown.Attack Path
- A user follows the setup instructions in
SKILL.md. - On Windows, the user creates a recurring Task Scheduler entry that invokes the VBS wrapper every one to five minutes; on Linux, the user installs and enables the systemd service.
...[truncated 1238 chars]
- A user follows the setup instructions in
- Remediation
View remediation
Remediation Suggestions
- Remove the default instructions for recurring Task Scheduler and systemd installation. Prefer an explicit, foreground health-check command that terminates after each user-authorized run.
- Remove
-WindowStyle Hiddenand-ExecutionPolicy Bypass. Use a signed PowerShell script and an appropriate execution policy instead of bypassing policy controls. - Include
guardian.ps1andguardian.jsin the reviewed Skill package rather than referring to unspecified external implementations. - Pin guardian scripts to fixed, administrator-owned paths and prevent modification by the service account or unprivileged users.
- Configure the scheduled task or service under a dedicated least-privileged account. For systemd, specify
User,Group,NoNewPrivileges=true, restrictive filesystem access, capability restrictions, and other applicable sandboxing controls. - Require explicit user approval before terminating processes, restarting services, rotating logs, or deleting temporary files.
- Add visible audit logging for every execution and remediation action. Avoid silent operation for security-relevant changes.
- Verify script integrity before execution using signatures or cryptographic hashes stored in a protected location.
- Document installation, disablement, and complete removal procedures for every scheduled task and service.
- Restrict restart frequency and implement failure limits to avoid persistent crash loops or denial-of-service conditions.
