T06 · System Persistence
- Location
references/workflow.md:34- Finding
Recurring Agent Cron Job Persists After Task Completion
- Content
View full analysis
" }, "delivery": { "mode": "none" } } ``` ``` The completion procedure does not remove or disable the scheduled job: ```text a. done_count++, completed.push(current), queue_index++ b. Send ✅ notification c. If done_count >= target_total → send 🎉 notification, done ``` The primary skill instructions also prescribe the recurring schedule: ```json { "schedule": { "kind": "every", "everyMs": 480000 }, "sessionTarget": "isolated", "payload": { "kind": "agentTurn", "timeoutSeconds": 120 } } ``` ### Technical Analysis The workflow installs an indefinitely recurring cron job that launches an isolated agent turn every eight minutes. This scheduled execution is intended to survive individual agent invocations so that it can monitor long-running video playback. However, the documented completion branch only sends a final notification and ends the current invocation. It does not delete, disable, or otherwise expire `video-check-loop`. No maximum invocation count, expiration time, cancellation procedure, or unrecoverable-error cleanup path is specified elsewhere in the audited project. Consequently, after all courses have completed, the scheduler can continue launching isolated agents across sessions. Each invocation may retain the ability to read the workspace state file and interact with the authenticated browser context identified by the stored Chrome `target_id`. ### Attack Path 1. A user invokes the skill to automate course pl ...[truncated 1233 chars]- Remediation
View remediation
= target_total`. 3. Add equivalent cleanup for user cancellation, invalid state, browser disconnection, repeated failures, and unrecoverable errors. 4. Configure a maximum lifetime, expiration timestamp, or invocation count as a fail-safe. 5. Make the completion operation idempotent so repeated invocations cannot continue performing browser or messaging actions. 6. Require explicit user confirmation before installing the recurring job and clearly disclose its interval and lifetime. 7. Add a documented manual cleanup command for stale jobs. 8. Prefer a bounded schedule when the platform supports one. A secure completion branch should follow this sequence: ```text if done_count >= target_total: send final notification disable or delete the stored cron job ID mark state as completed exit ``` Cron cleanup should occur in a `finally`-style failure path where appropriate so unexpected errors do not leave orphaned scheduled tasks. ]]>
