T06 · System Persistence
- Location
SKILL.md:38- Finding
Persistent Daily Agent Execution Through a Scheduled Task
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:38-43, 54-59
Vulnerability Type: Scheduled task persistence
Risk Level: MediumVulnerable Code
markdown ### 4. Periodic organization (scheduled task) - Automatically organize the knowledge base every day at 09:00 - Check Feishu cloud storage for duplicate documents - Optimize the knowledge-base structure - Report the organization resultsbash openclaw cron add --name "Daily Knowledge Base Organization" --cron "0 9 * * *" --message "Please perform knowledge base organization" --channel feishuTechnical Analysis
The Skill instructs the user to register an OpenClaw cron task that sends an execution request to the Agent through the Feishu channel every day at 09:00. The scheduled task survives the Skill invocation and causes future Agent activity without requiring a new, explicit request for each run.
The recurring operation is broadly authorized to inspect duplicate documents, reorganize the knowledge-base structure, and update Feishu content. The instructions do not define strict document boundaries, a dry-run mode, confirmation requirements, least-privilege credentials, or safeguards against unintended destructive changes. Although creation of the task is presented as optional, executing the documented command establishes cross-session persistence.
Attack Path
- A user enables the documented periodic organization feature.
- The user or Agent executes the supplied
openclaw cron addcommand. - OpenClaw creates a persistent schedule that triggers every day at 09:00.
- The schedule sends an organization request to the Agent through Feishu.
- The Agent inspects Feishu cloud documents and may update, deduplicate, or restructure the knowledge base.
- These operations continue across sessions until the scheduled task is explicitly removed.
Impact Assessment
The scheduled task obtains recurring access equival ...[truncated 662 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic cron registration from the default workflow and require explicit user authorization before creating any recurring task.
- Prefer one-time, user-initiated cleanup runs where practical.
- Display the exact schedule, channel, requested operations, accessible document scope, and removal command before obtaining consent.
- Restrict the scheduled operation to an allowlist of designated folders or knowledge-base nodes.
- Use a least-privilege Feishu identity that cannot access or modify unrelated documents.
- Perform duplicate detection and structural analysis in read-only or dry-run mode first.
- Require confirmation before deleting, merging, moving, or overwriting documents.
- Preserve backups or document versions so unintended changes can be rolled back.
- Record each scheduled execution and all resulting document changes in an audit log.
- Add execution limits, idempotency controls, and failure alerts to prevent repeated damaging operations.
- Provide and document a command for listing and removing the scheduled task.
- Periodically require renewed user authorization instead of allowing the schedule to operate indefinitely.
