T06 · System Persistence
- Location
SKILL.md:32- Finding
Persistent Daily Auto-Update Task
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill clearly says it will run daily auto-updates, but it creates persistent unattended authority to modify Clawdbot and every installed skill without per-update review.
Install only if you are comfortable allowing Clawdbot to modify itself and every installed skill automatically on a schedule. Prefer a check-only or dry-run schedule, pinned or allowlisted updates, and manual approval for core or skill changes; confirm you know how to remove the cron job before enabling it.
SKILL.md:32Persistent Daily Auto-Update Task
SKILL.md:53Unpinned Unattended Installation of Remote Updates
references/agent-guide.md:52Suppressed Update and Migration Failures
The skill explicitly performs self-modification by running clawdhub update --all, which updates all installed skills automatically. In this context, that is dangerous because the agent's capabilities and code can change without human review, expanding the blast radius of any compromised repository, malicious skill update, or accidental breaking release.
# Capture new version
CLAWDBOT_VERSION_AFTER=$(clawdbot --version 2>/dev/null || echo "unknown")
# Update skills
log "Updating skills via ClawdHub..."
SKILL_OUTPUT=$(clawdhub update --all 2>&1) || true
echo "$SKILL_OUTPUT" >> "$LOG_FILE"
The skill schedules unattended updates that will modify the Clawdbot installation and all installed skills, but the description does not prominently warn users that software changes will occur automatically on a recurring basis. This is dangerous because users may enable the skill without understanding that it grants a persistent mechanism for automatic code changes, increasing supply-chain and operational risk if an update is malicious, incompatible, or disruptive.
The guide instructs users to enable unattended updates that modify the bot and its installed skills on a schedule, but it does not require explicit trust controls, pinning, staging, approval, or rollback safeguards. This creates a real supply-chain and operational risk because remote package or skill changes can be pulled and applied automatically, potentially introducing malicious code or breaking behavior without user review.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
bun pm ls -g 2>/dev/null | grep clawdbot && echo "bun-global"
## Step 2: Create the Update Script (Optional)
For complex setups, create a helper script at `~/.clawdbot/scripts/auto-update.sh`:
The setup confirmation example states that daily updates will run at 4:00 AM in America/Los_Angeles. This prescribes a specific locale/time zone in user-facing language without offering a choice or explaining why that locale is required, which conflicts with the policy against forcing a locale without opt-in.
No suspicious patterns detected.