T06 · System Persistence
- Location
SKILL.md:174- Finding
Persistent Scheduled Jobs Repeatedly Access Credentials and External Services
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 174-177 and 222-242
Vulnerability Type: Persistent scheduled task installation
Risk Level: HighVulnerable Code
markdown ## Skill: AILove Scheduled Push Configuration Create **two** cron jobs (morning + evening) that check AILove and push updates to your chosen channel. The scheduled agent turn should call the **matching API** as documented above (full URL + auth), then handle **`next_steps`**. **Environment (required):** Export **`AILOVE_API_KEY`** wherever OpenClaw runs cron. Load it from `~/.openclaw/skills-data/ailove/credentials.json` or your preferred secret store. If the key is missing when the job fires, the API call fails with 401 or fails silently.bash openclaw cron add \ --name "AILove Morning Check" \ --cron "0 9 * * *" \ --tz "{timezone}" \ --session "isolated" \ --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps and summarize" \ --to "{channel-target-id}" \ --announcebash openclaw cron add \ --name "AILove Evening Check" \ --cron "0 21 * * *" \ --tz "{timezone}" \ --session "isolated" \ --message "Load AILOVE_API_KEY from ~/.openclaw/skills-data/ailove/credentials.json; call GET https://heerweiyi.cc/api/v1/agent/matching with Bearer; handle next_steps and summarize" \ --to "{channel-target-id}" \ --announceTechnical Analysis
The skill instructs the agent to install two recurring OpenClaw cron jobs. These jobs survive the original skill invocation and autonomously start isolated agent sessions twice per day. Each run reads a persistent API credential, authenticates to an external service, processes its response, and posts output to a configured communication channel.
Scheduled polling is related to the declared notification functionali ...[truncated 1904 chars]
- Remediation
View remediation
Remediation Suggestions
- Make interactive, user-invoked polling the default behavior.
- Require explicit informed consent immediately before creating each scheduled job.
- Display the exact schedule, destination, credential source, endpoint, and data categories before confirmation.
- Give scheduled jobs a configurable expiration date or maximum execution count.
- Provide documented commands to list, disable, and remove both jobs.
- Confirm that the selected destination is a private, intended channel before enabling announcements.
- Use a platform-managed secret store instead of directly reading a plaintext JSON credential file where available.
- Use a restricted token scoped only to the two documented API operations and support prompt revocation.
- Avoid silently failing when credentials are unavailable; record a sanitized error without including tokens.
- Require renewed consent before changing the endpoint, schedule, destination, or categories of data being posted.
