T06 · System Persistence
- Location
SKILL.md:61- Finding
Persistent Hourly Execution Through an OpenClaw Scheduled Task
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 61
Vulnerability Type: Persistent scheduled Agent execution
Risk Level: HighVulnerable Code
bash openclaw cron add --name context-monitor --cron "0 * * * *" --agent main --message "Execute the context-monitor skill"The displayed task message has been translated into English; the source contains an equivalent non-English instruction.
Technical Analysis
The installation instructions direct the user to create an hourly scheduled task targeting the
mainAgent. The task survives the initial Skill invocation and repeatedly instructs the Agent to execute the Skill.The audited package contains only
SKILL.md. The referencedmonitor.ps1,compress.ps1, and configuration files are absent. Consequently, the package cannot provide the documented monitoring and compression implementation, while the scheduled Agent invocation remains persistent. If executable files are subsequently introduced at the documented locations, the recurring task could cause them to be processed or executed without a new explicit installation decision.Attack Path
- A user trusts the installation instructions in
SKILL.md. - The user runs the supplied
openclaw cron addcommand. - OpenClaw creates an hourly task associated with the
mainAgent. - The task continues across sessions and repeatedly requests execution of the Skill.
- If content at the expected Skill path is later replaced or supplemented, subsequent scheduled invocations may process that changed content automatically.
Impact Assessment
The task obtains persistent execution within the authority and tool scope available to the
mainAgent. Potential consequences include recurring resource consumption, repeated unwanted Agent activity, and automatic invocation of content introduced after the initial review. The exact system impact depends on the privileges and tools granted to the `ma ...[truncated 177 chars]- A user trusts the installation instructions in
- Remediation
View remediation
Remediation Suggestions
- Remove automatic scheduled-task registration from the default setup procedure.
- Provide the complete, auditable monitoring implementation before offering recurring execution.
- Require explicit informed consent before creating any persistent task.
- Use a dedicated least-privileged Agent rather than the
mainAgent. - Pin the scheduled task to integrity-verified content and reject execution if file hashes change.
- Document how to inspect, disable, and remove the scheduled task.
- Add rate limits, failure cutoffs, and bounded resource consumption.
- Prefer a manual or nonpersistent execution mode as the secure default.
