Back to skill

Security audit

Cron

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local schedule tracker that writes disclosed JSON state under the OpenClaw memory directory and does not show hidden networking, privilege escalation, or destructive behavior.

Install only if you want a local schedule tracker that stores job titles, notes, tags, timing, status, and stats in your OpenClaw memory directory. Confirm before asking an agent to add, pause, or resume schedules, and specify a timezone if Asia/Tokyo is not appropriate.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared behavior substantially overstates what the implementation actually does, creating a trust gap between user/operator expectations and real functionality. Security-relevant mismatches can cause users to rely on nonexistent schedule management, pause/resume, or recurrence controls, which may lead to missed actions, unintended execution assumptions, or unsafe downstream agent decisions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill advertises local file-backed behavior and references multiple local storage paths, but it does not declare any explicit tool scope or permissions boundary. In an agent environment, undeclared file read/write capability weakens least-privilege guarantees and can cause the skill to receive broader filesystem access than users or orchestrators expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation text is overly broad and can cause the skill to trigger on a wide range of ordinary scheduling-related conversations, even when the user did not intend to invoke persistent or file-writing behavior. In context, this is more dangerous because the skill presents itself as managing recurring jobs and local state, so over-invocation can lead to inappropriate schedule creation, modification, or exposure of stored schedule data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The CLI defaults --timezone to Asia/Tokyo, which imposes a specific locale behavior even when the user does not choose one. Under the policy, forced language/locale settings should either be optional by default or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This helper writes JSON data to files under the user's home directory using a temporary file and atomic replace, which affects persistent user data. The code contains no confirmation prompt, logging, print statement, or explanatory comment/docstring disclosing that these writes occur.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The save_jobs function updates metadata and writes jobs data to disk, changing persistent state in the user's home directory. There is no user-facing warning, logging, or inline documentation in this file describing this behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The save_runs function updates metadata and stores run history on disk, which is a persistent write affecting user data. This file does not include any warning, log message, or explanatory documentation for that operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The save_stats function writes statistics data to a file in the user's home directory, creating or modifying persistent local state. No prompt, logging, or explanatory comment/docstring is present in this code to disclose that behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.