Back to skill

Security audit

Cron Scheduler

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it gives agents direct recipes for persistent cron changes without enough review or safety controls.

Install only if you want an agent to help manage real cron jobs. Before allowing it to run changes, ask to see the exact crontab entry or removal diff, back up the current crontab, test commands manually, and be especially careful with deletion, service restart, and privileged log-path examples.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

List all cron jobs

bash
echo "=== User crontab ==="
crontab -l 2>/dev/null || echo "(empty)"
echo ""
echo "=== System cron ==="
ls /etc/cron.d/ 2>/dev/null

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to add, edit, and remove cron jobs, which creates persistent system changes that continue executing after the session ends. Without clear user-confirmation, persistence warnings, or safeguards around what commands may be scheduled, an agent could unintentionally install long-lived tasks or remove legitimate scheduled jobs.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
98% confidence
Finding

This command appends a new cron entry and installs it immediately, creating persistent execution on the host. Because the placeholder allows arbitrary commands and the skill does not require confirmation or validation, it could be used to establish unintended or harmful persistence.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

Add a cron job

bash
# Add to user crontab
(crontab -l 2>/dev/null; echo "SCHEDULE COMMAND") | crontab -

# Common schedules:

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

crontab -e opens the user's cron configuration for modification, enabling persistent changes that may be hard to audit in an automated-agent context. If an agent invokes this path or guides users into it without review controls, it can facilitate stealthy or accidental persistence.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

Remove a cron job

bash
# Edit crontab interactively
crontab -e

# Or remove a specific line
crontab -l | grep -v "PATTERN_TO_REMOVE" | crontab -

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

Piping crontab -l through grep -v and reinstalling it removes matching entries, which modifies persistent scheduled execution and can accidentally delete unrelated jobs if the pattern is too broad. In an agent setting, loose pattern matching makes this particularly error-prone and potentially disruptive.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

crontab -e

Or remove a specific line

crontab -l | grep -v "PATTERN_TO_REMOVE" | crontab -

text

### Check cron logs

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The examples include scheduled actions such as deleting files in /tmp, restarting services, and writing into system log locations, all of which can be destructive or disruptive if used incorrectly. Presenting these patterns without cautions or validation guidance increases the chance that an agent will apply them unsafely or too broadly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
96% confidence
Finding

This example adds environment variables and a scheduled backup command into crontab, again creating persistent execution. It also encourages writing to /var/log, which may require elevated privileges and can fail or behave unexpectedly if used in the wrong context.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

Environment variables in cron

bash
# Cron runs with minimal environment. Set what you need:
(crontab -l 2>/dev/null; echo "PATH=/usr/local/bin:/usr/bin:/bin
SHELL=/bin/bash
0 2 * * * /home/user/backup.sh >> /var/log/backup.log 2>&1") | crontab -

Session Persistence

Medium
Category
Rogue Agent
Confidence
97% confidence
Finding

The example directly shows how to install a nightly backup cron job, which is a form of persistence because it causes future unattended execution. In a skill intended for automation, this is contextually expected, but it is still security-relevant because unattended jobs can be abused or misconfigured.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
## Examples

**User:** "Run my backup script every night at 2am"
→ `(crontab -l 2>/dev/null; echo "0 2 * * * /home/user/backup.sh >> /var/log/backup.log 2>&1") | crontab -`

**User:** "Check disk space every hour and alert me if it's over 80%"
→ Create a check script + cron job

Static analysis

No suspicious patterns detected.