T06 · System Persistence
- Location
clawhub.json:56- Finding
Undocumented Managed Execution Every 30 Minutes
- Content
View full analysis
Vulnerability Details
File Location:
clawhub.json:56-59
Vulnerability Type: Undocumented scheduled persistence
Risk Level: Highjson "cron": "*/30 * * * *", "automaton": { "managed": true, "entrypoint": "trade_skill.py" }Technical Analysis
The Skill declares a managed scheduled task that executes
trade_skill.pyevery 30 minutes. This recurring behavior is not disclosed inSKILL.md, which presents the Skill as a manually invoked, dry-run planning utility.Every scheduled invocation initializes an authenticated
SimmerClient, retrieves account and market information, and can callimport_kalshi_market()when a selected market is not already indexed. Although the implementation does not place financial orders and explicitly rejects--live, importing a market is still a remote state-changing operation.Persistent unattended execution exceeds the minimum privilege required to produce a trade plan on explicit user request. It also increases the duration and frequency with which the Skill and its third-party dependency have access to
SIMMER_API_KEY.Attack Path
- The hosting platform loads
clawhub.jsonand honors the managed automaton configuration. - The cron expression launches
trade_skill.pyevery 30 minutes without a new user request. - The platform supplies
SIMMER_API_KEYto the process. - The program creates an authenticated Simmer client and retrieves balance, market, and context data.
- For an unindexed candidate, the program invokes
import_kalshi_market(), modifying remote Simmer state without per-run confirmation. - Scheduled access continues until the automaton is explicitly disabled or removed.
Impact Assessment
The configuration provides cross-session recurring execution with access to the Simmer API credential. Its scope includes repeated authenticated account-data retrieval, market discovery, context queries, and remote market imports. ...[truncated 270 chars]
- The hosting platform loads
- Remediation
View remediation
Remediation Suggestions
- Remove the
cronand managed automaton configuration from the default package. - Require an explicit user invocation for each planning run.
- If scheduling is a required feature, make it opt-in and clearly document its frequency, network activity, credential usage, and shutdown procedure.
- Require explicit confirmation before remote state-changing operations such as
import_kalshi_market(). - Separate read-only planning from market import so the default workflow requires only read-only API permissions.
- Use a narrowly scoped, revocable API key and document how users can disable the schedule and revoke the credential.
- Add rate limits and an execution audit log for any intentionally scheduled mode.
- Remove the
