T06 · System Persistence
- Location
README.md:84- Finding
Persistent Daily Execution Through User Crontab
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 84-88
Vulnerability Type: Persistent scheduled-task installation
Risk Level: MediumVulnerable Code
bash # Install crontab (crontab -l 2>/dev/null; echo "0 20 * * * cd ~/.qclaw/skills/bedtime-story-teller && python3 scripts/sleep_routine.py --mode cron >> /tmp/sleep_routine.log 2>&1") | crontab - # View crontab crontab -lTechnical Analysis
The documented command modifies the invoking user's crontab and registers the Skill for automatic execution every day at 20:00. This execution persists across terminal sessions and system restarts supported by the cron service.
Scheduling is related to the optional bedtime-reminder feature, but it is not required for the Skill's primary story-generation and playback functionality. It therefore exceeds the minimum execution scope needed by the core feature.
The installation command also has several security and reliability weaknesses:
- It suppresses errors from
crontab -l. If the existing crontab cannot be read, the pipeline may install only the new entry and unintentionally discard existing jobs. - It is not idempotent. Running it repeatedly appends duplicate scheduled tasks.
- It executes code from a user-writable, fixed project path. If files at that path are subsequently replaced or modified, cron will execute the changed code automatically.
- It writes to a predictable shared path,
/tmp/sleep_routine.log, rather than a private per-user state or log directory. - No corresponding removal command or lifecycle management procedure is documented.
The Python script itself does not install the cron job, elevate privileges, access the network, or retrieve remote payloads. Installation occurs only if a user copies and executes the README command.
Attack Path
- A user follows the cron setup instructions in
README.md. - The shell pipeline reads the current ...[truncated 1526 chars]
- It suppresses errors from
- Remediation
View remediation
Remediation Suggestions
- Keep scheduling strictly optional and require explicit, informed user confirmation. Clearly distinguish the reminder feature from the core story-generation functionality.
- Replace the raw pipeline with a dedicated installer that aborts if the existing crontab cannot be read:
bash current_crontab="$(crontab -l 2>/dev/null)" || { status=$? if [ "$status" -ne 1 ]; then echo "Unable to read the existing crontab; no changes were made." >&2 exit "$status" fi current_crontab="" } - Add uniquely marked begin/end comments and check for an existing entry before installation so setup is idempotent and does not create duplicate jobs.
- Preserve the original crontab and offer a preview or backup before applying changes.
- Document an uninstall command that removes only this Skill's marked entry without affecting unrelated scheduled tasks.
- Use an absolute, validated interpreter and script path. Ensure the Skill directory and executable files are writable only by the intended user.
- Write logs to a private directory such as
~/.qclaw/kids/logs/, create it with restrictive permissions, and implement log rotation or avoid persistent logging when it is unnecessary. - Consider a user-visible scheduling facility that provides clear enable, disable, and status controls instead of instructing users to rewrite their crontab directly.
- Document how users can verify the installed entry and disable reminders immediately.
