create-persona
Warn
Audited by Gen Agent Trust Hub on Apr 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
openclawutility to create and edit cron jobs. These commands interpolate user-provided variables like{name},{task}, and{instruction}directly into command arguments, which serves as a classic command injection vector. - [COMMAND_EXECUTION]: The skill performs extensive filesystem operations, including directory creation (
mkdir) and file writes to various project paths (e.g.,~/Projects/agents/), which could be abused to overwrite existing configuration. - [COMMAND_EXECUTION]: The skill establishes persistence on the host system by configuring scheduled background tasks (cron jobs) that execute autonomously.
- [COMMAND_EXECUTION]: The skill directs the agent to modify existing infrastructure by editing the messages of existing cron jobs (
openclaw cron edit), which could alter the behavior of previously configured agents.
Audit Metadata