T06 · System Persistence
- Location
scripts/init_owner.sh:171- Finding
Recurring Cron Persistence Is Installed by Default
- Content
View full analysis
/dev/null 2>&1; then warn "crontab is not available on this machine; cron setup skipped." return fi section "Cron" ( crontab -l 2>/dev/null | grep -v -F "${PROFILE}-sync.sh"; echo "$CRON_ENTRY" ) | crontab - crontab -l | grep -F "${PROFILE}-sync.sh" || warn "Cron entry write verification did not echo back." } ``` The recurring command is constructed at `scripts/init_owner.sh:91-94`: ```bash OWNER_PROFILE_PATH="$HOME/.clawdate/profiles/${PROFILE}-owner-profile.json" WRAPPER_SCRIPT_PATH="$HOME/.clawdate/bin/${PROFILE}-sync.sh" LOG_PATH="$HOME/.clawdate/logs/${PROFILE}.log" CRON_ENTRY="*/5 * * * * /bin/bash -lc \"$WRAPPER_SCRIPT_PATH\"" ``` Equivalent persistence instructions are also documented in `SKILL.md:232-243` and bundled in `assets/cron.example.txt:1-3`: ```bash CRON_ENTRY='*/5 * * * * /bin/bash -lc "$HOME/.clawdate/bin/__PROFILE__-sync.sh"' ( crontab -l 2>/dev/null | grep -v -F "__PROFILE__-sync.sh"; echo "$CRON_ENTRY" ) | crontab - crontab -l | grep -F "__PROFILE__-sync.sh" ``` ### Technical Analysis The recommended bootstrap path modifies the current user's crontab and schedules the generated synchronization wrapper to execute every five minutes. This scheduled task survives completion of the Skill run and continues across shell and Agent sessions. Ongoing synchronization is related to the declared ClawDate functionality, and the script offers a `--skip-cron` option. Nevertheless, persistence is enabled by default rather than being installed only after explicit, informed user consent. The project also provides no corresponding removal script or documented c ...[truncated 1563 chars]- Remediation
View remediation
