T06 · System Persistence
- Location
SKILL.md:20- Finding
Recurring Scheduled Task Establishes Cross-Session Persistence
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:20-23
Vulnerability Type:T06: System Persistence
Risk Level: HighVulnerable Code:
bash openclaw cron add --schedule "30 17 * * 1-5" --message "生成今日工作总结" --channel feishuTechnical Analysis
The documented installation command registers a recurring OpenClaw cron task that runs at 17:30 every weekday. Unlike a one-time invocation, this task remains registered after the current Skill execution and continues triggering Agent and Feishu-channel activity across later sessions.
Although the scheduling behavior is documented, it creates a persistent execution mechanism. The instructions do not provide a corresponding command for inspecting, disabling, or removing the scheduled task.
Attack Path
- A user follows the automatic scheduling instructions in
SKILL.md. openclaw cron addregisters the recurring task in OpenClaw.- The task survives the current terminal or Agent session.
- At every scheduled interval, OpenClaw processes the configured summary request and directs the resulting activity to the Feishu channel.
- Execution continues until the user discovers and explicitly removes or disables the task.
Impact Assessment
The mechanism obtains persistent recurring execution within the permissions of the OpenClaw process and its configured Feishu integration. It does not demonstrate operating-system privilege escalation, but it can repeatedly consume Agent resources, access data available to the invoked workflow, and cause channel activity without a new manual invocation. The scope is limited by the privileges and channel configuration of the OpenClaw environment.
- A user follows the automatic scheduling instructions in
- Remediation
View remediation
Remediation Suggestions
- Make one-time manual execution the default behavior.
- Require explicit, informed user consent before registering a recurring task.
- Display the exact schedule, invoked message, destination channel, and persistence implications before installation.
- Provide documented commands to list, disable, and permanently remove the cron entry.
- Use a uniquely identifiable task name so users can reliably locate the entry.
- Restrict the scheduled operation to the minimum data access and channel permissions required.
- Consider requiring confirmation before each external channel delivery.
