feishu-cron-reminder
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local CLI utility using Node.js, specifically targeting a script within the AutoClaw application bundle:
/Applications/AutoClaw.app/Contents/Resources/gateway/openclaw/openclaw.mjs. This is used to add, list, and remove scheduled tasks. - [PERSISTENCE]: The skill's primary function is to establish persistence on the host system through the creation of recurring cron jobs via the
openclaw cron addcommand. These jobs are designed to trigger actions at specified intervals. - [INDIRECT_PROMPT_INJECTION]: The skill uses a template to store natural language instructions within the cron job's
system-eventfield. This data is processed by the AI agent's "main session" at a later time, creating a vulnerability surface. - Ingestion points: User-provided inputs for
<任务名>(Task Name) and<提醒内容>(Reminder Content) are interpolated into the--system-eventcommand string inSKILL.md. - Boundary markers: The skill uses a prefix
[CRON定时任务]to identify these events but lacks strict delimiters or escaping to prevent user content from overriding the intended instructions. - Capability inventory: Instructions stored in the cron task target the "main session," which the skill explicitly identifies as having higher privileges (access to the
messagetool) compared to isolated sub-agents. - Sanitization: There is no evidence of sanitization or validation logic to ensure that user-provided strings do not contain secondary instructions that the agent might execute when the cron job triggers.
Audit Metadata