Missing User Warnings
Medium
- Confidence
- 88% confidence
- Finding
- The security policy acknowledges that the skill writes to `/etc/cron.d/openclaw-vm-memory-oracle`, writes logs under `/var/log/openclaw/`, and deletes backup files, but it presents these as ordinary behavior without clearly flagging that they affect system-wide scheduling, require elevated privileges in many environments, and include destructive retention operations. This is dangerous because reviewers or deployers may underestimate operational risk and grant the skill broader trust than warranted, especially since cron registration can create persistent execution on the host.
