T06 · System Persistence
- Location
SKILL.md:79- Finding
Indefinite Self-Renewing Cron Persistence
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is openly designed to send recurring surprise messages, but it needs Review because it creates an indefinite self-renewing cron chain, stores learned preferences, and may read sensitive calendar credentials.
Install only if you intentionally want an autonomous companion that can message you indefinitely. Before enabling it, set your own timezone, location, channel, and target; consider disabling calendar unless you have a safer brokered integration; review the topics file because it stores learned preferences; and make sure you know how to stop all Smart Surprise cron jobs.
SKILL.md:79Indefinite Self-Renewing Cron Persistence
SKILL.md:155Raw OAuth Credentials and Local Helper Script Exposed to Agent Context
SKILL.md:62Unvalidated Generated Content Interpolated into a Shell-Like Command
references/config.md:42User Location Disclosed to an External Weather Service Without Explicit Per-Integration Consent
The activation description authorizes proactive outreach in broad terms and ties execution not only to initial setup but also to whenever the agent 'wants' to reach out. In a messaging skill with cron-based automation, that ambiguity weakens user consent boundaries and can result in repeated unsolicited contact without a clear, user-scoped trigger condition.
The skill description emphasizes surprise-driven, indefinite automatic messaging but does not prominently warn that it will continue sending messages forever unless stopped. For a proactive skill that can message external channels automatically, missing disclosure undermines informed consent and raises spam, harassment, and trust risks.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
openclaw cron rm <job-id> # repeat for each job found
# Step 2: Remove the skill directory
rm -rf ~/.openclaw/workspace/skills/smart-surprise
# Step 3: Optionally remove runtime state
rm -f ~/.openclaw/workspace/skills/smart-surprise/next_run.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
openclaw cron rm <job-id> # repeat for each job found
# Step 2: Remove the skill directory
rm -rf ~/.openclaw/workspace/skills/smart-surprise
# Step 3: Optionally remove runtime state
rm -f ~/.openclaw/workspace/skills/smart-surprise/next_run.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/workspace/skills/smart-surprise
rm -f ~/.openclaw/workspace/skills/smart-surprise/next_run.json
This fully removes Smart Surprise from your system.
The skill explicitly persists behavioral state across runs via topics/preferences and a self-perpetuating cron chain that learns from conversation history. Persistent autonomy and memory increase risk because the system can continue acting on accumulated user data without fresh consent at each run, especially in a background messaging context.
Smart Surprise transforms a passive AI assistant into a **proactive companion** that reaches out to users at unpredictable moments — with greetings, care, tips, news, or just a friendly chat. Over time it learns what the user likes and tailors content accordingly, making every interaction feel more personal.
Unlike fixed scheduled tasks that feel mechanical, Smart Surprise uses a **chain of self-deleting one-shot cron jobs** to create organic, surprise-driven interactions. The chain runs indefinitely and **learns continuously** from what the user responds to.
## How the Core Loop Works
The skill records preference signals from user behavior and conversation responses, including non-response, but does not provide a clear privacy notice or retention policy. This creates covert profiling risk because users may not realize their interactions are being persistently analyzed and stored to shape future outreach.
Defaulting to a specific timezone/locale without user opt-in can lead to messages being sent at inappropriate local times and can mis-handle quiet hours. In a proactive messaging skill, that context makes the issue more consequential because incorrect locale assumptions directly affect when unsolicited messages are delivered.
The config sets "timezone": "Asia/Shanghai" and "location": "Hangzhou", which imposes a specific locale context. Under the policy, forcing a locale is a finding unless the skill offers user choice or clearly documents a justified region-specific scope, which is not evident in this file.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
---
## Step 1: Create the Config File
Create `~/.openclaw/workspace/skills/smart-surprise/config.json`:
The setup explicitly instructs the user to create an initial cron trigger that starts a self-perpetuating chain, establishing durable automated execution beyond the initiating session. This kind of persistence is security-relevant because it continues acting without further user confirmation and can be abused for repeated messaging, data collection, or stealthy long-term operations.
---
## Step 2: Create the Initial Cron Trigger
Run this **once** to start the self-perpetuating chain. The initial trigger should be **~5 minutes after setup** so the agent has time to initialize. Generate the UTC timestamp dynamically:
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
--session isolated
--delete-after-run
--at "$INIT_TIME"
--message "Read ~/.openclaw/workspace/skills/smart-surprise/SKILL.md and execute Phase 2: Runtime workflow. Deliver a greeting message to the user, then schedule the next random trigger and delete this job."
--timeout-seconds 900
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
--session isolated
--delete-after-run
--at "$INIT_TIME"
--message "Read ~/.openclaw/workspace/skills/smart-surprise/SKILL.md and execute Phase 2: Runtime workflow. Deliver a greeting message to the user, then schedule the next random trigger and delete this job."
--timeout-seconds 900
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
--session isolated
--delete-after-run
--at "$INIT_TIME"
--message "Read ~/.openclaw/workspace/skills/smart-surprise/SKILL.md and execute Phase 2: Runtime workflow. Deliver a greeting message to the user, then schedule the next random trigger and delete this job."
--timeout-seconds 900
The documented design intentionally creates a self-perpetuating cron chain that repeats forever, giving the skill indefinite execution persistence and ongoing access to messaging and preference-update behavior. Even without overtly malicious payloads, this can lead to unwanted resource consumption, spam, hard-to-notice long-term automation, and increased blast radius if the skill logic is later modified or compromised.
1. The initial cron fires at the scheduled time
2. The agent reads config + topics.md, composes a message, sends it, updates preferences, schedules the next random trigger, then deletes itself
3. The next trigger fires at the random time (between `minIntervalMinutes` and `maxIntervalMinutes`)
4. Repeat forever
The agent continuously learns your preferences over time by updating topics.md after each interaction.
The troubleshooting instructions reinforce recreating the persistent cron-based execution path, further normalizing long-lived autonomous operation. This increases risk because users are encouraged to restore persistence whenever the chain breaks, preserving continuous execution with minimal oversight.
openclaw cron list | grep -i surprise
openclaw cron rm <job-id> # repeat for each job found
# Recreate with correct session target (isolated)
openclaw cron add \
--name "Smart Surprise" \
--session isolated \
The markdown file provides uninstallation commands using rm -rf and rm -f to remove the skill directory and runtime state. While the commands are clearly shown, the section does not explicitly warn users that these deletions are irreversible and will permanently remove local skill data.
The file explicitly instructs the agent to silently update user preference data after each interaction and stores those updates in a persistent file, while providing no clear upfront notice or consent mechanism in the skill itself. This creates a privacy and transparency issue: users may be profiled or have behavioral inferences recorded without meaningful awareness, and the persistence of those updates increases the risk of misuse, surprise, or unauthorized modification.
This markdown file documents that each run writes next_run.json, which is a user-data-affecting file operation. Although it says 'Do not edit manually,' it does not clearly frame the write as a behavioral warning to users in the broader skill description, so the persistence side effect may be easy to miss.
The sample configuration hard-codes Asia/Shanghai and Beijing, which can be read as prescribing a specific locale by default. The document does not explicitly tell users to choose their own timezone/location in that example block, creating a mild locale-policy concern.
Detected: suspicious.destructive_delete_command