T06 · System Persistence
- Location
SKILL.md:35- Finding
Persistent Autonomous Chess Operations Through a Scheduled Agent Task
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 35-47
Vulnerability Type: Persistent scheduled task
Risk Level: HighVulnerable Code
bash clawdbot cron add \ --name "molt-chess-poll" \ --every 1800000 \ --session isolated \ --message "Check molt.chess: GET /api/agents/status. If games_awaiting_move > 0, get game state, use play.py to find best move, and POST the move. Follow HEARTBEAT.md instructions." \ --model sonnetmarkdown This creates an isolated agent session that: - Runs every 30 minutes - Checks if it's your turn - Analyzes position with play.py - Makes your move automaticallyTechnical Analysis
The installation instructions direct the user or Agent to create a recurring cross-session task. The task periodically starts an isolated Agent session, accesses the chess service using stored credentials, analyzes games, and performs authenticated actions without further interaction.
This behavior persists beyond the Skill's initiating session. Although
SKILL.mdlater says that heartbeat scheduling should require owner consent and provides a removal command, the earlier section labels auto-polling as required. These contradictory instructions could cause scheduling to occur before meaningful consent is obtained.Periodic polling is useful for avoiding chess timeouts, but installing a persistent Agent task is not the minimum privilege necessary for manual chess analysis or user-initiated play.
Attack Path
- A user or installation Agent follows the section labeled “REQUIRED: Set Up Auto-Polling.”
- The supplied
clawdbot cron addcommand creates a recurring task. - Every 30 minutes, a new isolated Agent session follows the supplied gameplay message.
- The session accesses the stored chess API credential and contacts the remote service.
- When a move is pending, the task retrieves game data and submits an authenticated move without c ...[truncated 575 chars]
- Remediation
View remediation
Remediation Suggestions
- Make scheduling strictly opt-in and request explicit owner confirmation before displaying or executing the cron command.
- Default to manual, user-initiated status checks.
- Remove language describing persistent polling as unconditionally required.
- Clearly disclose the task's frequency, credential use, network destinations, authenticated actions, resource consumption, and removal procedure.
- Schedule a fixed local script with narrowly defined behavior rather than a general Agent prompt.
- Require renewed consent before changing the scheduled task's instructions or permissions.
- Ensure task removal is verified during uninstall or when the owner disables automatic play.
