T06 · System Persistence
- Location
scripts/install_self_evolver.py:97- Finding
Recurring Agent Task Creates Cross-Session Persistence
- Content
View full analysis
Vulnerability Details
File Location:
scripts/install_self_evolver.py:97-131
Vulnerability Type: Scheduled cross-session agent execution
Risk Level: HighVulnerable Code
python def register_cron(): """注册每3天运行 SEA 进化的定时任务""" try: from openclaw.cron import CronManager import os # 检测是否是 openclaw 环境 try: import openclaw except ImportError: print(" ℹ️ openclaw 模块不可用,跳过 cron 注册") print(" 请手动添加 cron 任务:") print(" openclaw cron add --name 'SEA-Evolution' --every 3days") return cm = CronManager() job = { "name": "SEA-Evolution-Scan", "schedule": {"kind": "every", "everyMs": 3 * 24 * 60 * 60 * 1000}, "payload": { "kind": "agentTurn", "message": "运行自我进化:python ~/.qclaw/workspace/scripts/sea_evolve.py --quiet", }, "sessionTarget": "isolated", "enabled": True, } # 检查是否已存在 existing = [j for j in cm.list() if j.get("name") == "SEA-Evolution-Scan"] if existing: print(" ℹ️ cron 任务已存在,跳过") else: cm.add(job) print(" ✅ cron 任务已注册(每3天运行)") except Exception as e: print(f" ℹ️ cron 注册失败(非致命):{e}") print(" 请手动添加:每3天运行 python ~/.qclaw/workspace/scripts/sea_evolve.py --quiet")Technical Analysis
Installation creates an enabled OpenClaw scheduled task that initiates an isolated agent turn every three days. The task survives the installation session and asks the agent to execute a Python script from the writable user workspace.
Although the recurring behavior is disclosed in the documentation, the installer registers it automatically without an explicit confirmation immediately before persistence is established. The scheduled payloa ...[truncated 1157 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not register the recurring task by default. Require explicit, informed confirmation immediately before calling
cm.add(). - Offer manual execution as the default installation mode.
- Execute an immutable or integrity-verified script instead of trusting a mutable workspace path.
- Verify ownership and restrictive permissions on the workspace and scheduled script.
- Store and verify a cryptographic digest before each scheduled execution.
- Provide a documented uninstall operation that removes
SEA-Evolution-Scan. - Display the exact schedule, payload, target session, and removal command before registration.
- Consider requiring approval for each evolution cycle rather than launching an autonomous agent turn.
- Do not register the recurring task by default. Require explicit, informed confirmation immediately before calling
