T06 · System Persistence
- Location
scripts/setup-cron.sh:82- Finding
Persistent scheduled task performs recurring GitLab collection and unconditional Feishu publication
- Content
View full analysis
> \"$SKILL_DIR/logs/cron.log\" 2>&1 # $CRON_COMMENT" echo "⏰ Setting scheduled task:" echo " Schedule: $cron_expr" echo " Command: generate report and upload to Feishu" echo "" # Remove the previous task of the same type (crontab -l 2>/dev/null | grep -v "$CRON_COMMENT") | crontab - # Add the new task (crontab -l 2>/dev/null; echo "$CMD") | crontab - ``` The related removal logic is also present at `scripts/setup-cron.sh:66-70`: ```bash remove_cron() { echo "🗑️ Removing scheduled task..." (crontab -l 2>/dev/null | grep -v "$CRON_COMMENT") | crontab - echo "✅ Scheduled task removed" } ``` ### Technical Analysis The script directly modifies the invoking user's crontab and installs a recurring command that survives the current Skill or Agent session. The default schedule is weekly, but a caller can supply another cron expression. Scheduled report generation can be a legitimate optional capability. However, `SKILL.md` does not document cron installation as part of the declared workflow, and the persistent job performs more than local report generation: it always invokes `upload-to-feishu.sh`. The job does not check the configured `feishu.enabled` value. The example configuration sets that option to `false`, but a cron job installed by this script still attempts publication on every execution. Consequently, an optional network publication operation becomes a persistent, recurring operation. This exceeds the minimum privileges required for on-demand weekly report generation. It also extends access to GitLab and Feishu credentials beyond the session in which the user requested ...[truncated 1345 chars]- Remediation
View remediation
