feishu-cron-reminder

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local CLI utility using Node.js, specifically targeting a script within the AutoClaw application bundle: /Applications/AutoClaw.app/Contents/Resources/gateway/openclaw/openclaw.mjs. This is used to add, list, and remove scheduled tasks.
  • [PERSISTENCE]: The skill's primary function is to establish persistence on the host system through the creation of recurring cron jobs via the openclaw cron add command. These jobs are designed to trigger actions at specified intervals.
  • [INDIRECT_PROMPT_INJECTION]: The skill uses a template to store natural language instructions within the cron job's system-event field. This data is processed by the AI agent's "main session" at a later time, creating a vulnerability surface.
  • Ingestion points: User-provided inputs for <任务名> (Task Name) and <提醒内容> (Reminder Content) are interpolated into the --system-event command string in SKILL.md.
  • Boundary markers: The skill uses a prefix [CRON定时任务] to identify these events but lacks strict delimiters or escaping to prevent user content from overriding the intended instructions.
  • Capability inventory: Instructions stored in the cron task target the "main session," which the skill explicitly identifies as having higher privileges (access to the message tool) compared to isolated sub-agents.
  • Sanitization: There is no evidence of sanitization or validation logic to ensure that user-provided strings do not contain secondary instructions that the agent might execute when the cron job triggers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:23 AM
Security Audit — agent-trust-hub — feishu-cron-reminder