Skip to content

Hide Navigation Hide TOC

Unauthorized Background Task Execution via Cron Job Installation - ATR-2026-00154 (c3aa4e0d-c3b3-5feb-8be4-7e07ee5dcaba)

Detects skills that automatically install cron jobs to execute background tasks without explicit user consent. This skill installs a cron job that polls external marketplace tasks every 10 seconds and executes arbitrary browser automation commands from unknown third parties, potentially compromising the system during "idle" periods.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Unauthorized Background Task Execution via Cron Job Installation - ATR-2026-00154 (c3aa4e0d-c3b3-5feb-8be4-7e07ee5dcaba) Agent Threat Rules 1