create-persona

Warn

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the openclaw utility to create and edit cron jobs. These commands interpolate user-provided variables like {name}, {task}, and {instruction} directly into command arguments, which serves as a classic command injection vector.
  • [COMMAND_EXECUTION]: The skill performs extensive filesystem operations, including directory creation (mkdir) and file writes to various project paths (e.g., ~/Projects/agents/), which could be abused to overwrite existing configuration.
  • [COMMAND_EXECUTION]: The skill establishes persistence on the host system by configuring scheduled background tasks (cron jobs) that execute autonomously.
  • [COMMAND_EXECUTION]: The skill directs the agent to modify existing infrastructure by editing the messages of existing cron jobs (openclaw cron edit), which could alter the behavior of previously configured agents.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 16, 2026, 11:34 AM