T09 · Insecure Skill Coding Practices
- Location
HEARTBEAT.md:17- Finding
Heartbeat setup replaces the user's entire crontab
- Content
View full analysis
> /tmp/wukong-cron.txt << 'EOF' # Heartbeat check - check notifications every 5 minutes */5 * * * * python3 heartbeat-check.py >> /tmp/wukong-heartbeat.log 2>&1 EOF crontab /tmp/wukong-cron.txt ``` `HEARTBEAT.md:17-29`: ```bash cat > /tmp/wukong-cron.txt << 'EOF' # Wukong invite monitor - base check */5 * * * * cd ~/.openclaw/workspace/skills/wukong-invite-monitor/scripts && python3 monitor_lite.py check >> /tmp/wukong-monitor.log 2>&1 # Heartbeat notification check */5 * * * * cd ~/.openclaw/workspace/skills/wukong-invite-monitor/scripts && python3 heartbeat-check.py >> /tmp/wukong-heartbeat.log 2>&1 EOF # Apply configuration crontab /tmp/wukong-cron.txt ``` ### Technical Analysis The command `crontab FILE` replaces the current user's complete crontab with the contents of the supplied file. It does not append the new entries to existing scheduled tasks. The heartbeat guide creates a file containing only the Wukong tasks and then installs it as the complete crontab. The README uses append redirection, but it still installs the resulting temporary file as the entire crontab and does not first preserve the user's existing entries. Recurring scheduling is relevant to the declared monitoring function and is explicitly optional, so persistence itself is not considered malicious. However, replacing unrelated scheduled tasks exceeds the minimum configuration change required to install this Skill. ### Attack Path 1. A user already has unrelated cron jobs, such as backup, monitoring, certificate-renewal, or maintenance tasks. 2. The user follows the documented heartbeat setup instructions. 3. The instructions create `/tmp/wukong-cron.txt` containing the Wukong entries. 4. `crontab /tmp/wukong-cron.txt` replaces the user's comple ...[truncated 614 chars]- Remediation
View remediation
