T06 · System Persistence
- Location
references/agent-guide.md:72- Finding
Persistent Daily Update Task Executes Across Sessions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is openly an auto-updater, but it sets up recurring unattended changes to Clawdbot and all installed skills without tight approval or version controls.
Install only if you are comfortable with Clawdbot automatically modifying itself and all installed skills on a schedule. Prefer a dry-run or notify-first setup, pin or approve specific updates where possible, and verify you know how to inspect and remove the cron job before enabling it.
references/agent-guide.md:72Persistent Daily Update Task Executes Across Sessions
references/agent-guide.md:31Unpinned Remote Updates Permit Mutable Upstream Code Installation
references/agent-guide.md:43Suppressed Update Failures Can Leave a Partially Modified Installation
clawdhub update --all performs self-modification by updating all installed skills automatically, which can introduce unreviewed code or changed behavior into the agent environment. In the context of a cron-driven auto-updater, this is especially dangerous because it repeatedly applies remote changes without interactive verification, amplifying supply-chain compromise risk.
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")
# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"
The skill description emphasizes convenience but does not prominently warn that it will automatically and repeatedly modify the local Clawdbot installation and all installed skills. Missing upfront disclosure weakens informed consent and increases the chance a user enables unattended code changes from external sources without understanding the persistence and supply-chain risk.
The quick-start phrase is broad enough that a normal user request about setting up updates could invoke a skill that creates a scheduled task and later performs software-modifying actions. Because the skill establishes persistent automation and updates both the bot and all installed skills, accidental triggering has a higher-than-normal security impact compared with a read-only helper skill.
The guide instructs an agent to set up unattended daily updates that modify the installed bot and all skills, including running maintenance commands like clawdbot doctor --yes, without requiring explicit per-run user approval or emphasizing the risks of automatic system changes. This creates a supply-chain and integrity risk: a compromised package, malicious skill update, or unexpected migration could be applied automatically and persistently.
The guide directs creation of a persistent helper script under ~/.clawdbot/scripts/auto-update.sh, establishing reusable automation that survives beyond the immediate session. Persistence itself is not inherently malicious, but here it supports recurring unattended privileged actions and broadens the blast radius if the script or its execution path is later tampered with.
bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"
## Step 2: Create the Update Script (Optional)
For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:
No suspicious patterns detected.