ATR-2026-00154highSkill Compromisedraft
Unauthorized Background Task Execution via Cron Job Installation
Detects skills that automatically install cron jobs to execute background tasks without explicit user consent. This skill installs a cron job that polls external marketplace tasks every 10 seconds and executes arbitrary browser automation commands from unknown third parties, potentially compromising the system during "idle" periods.
Severity
high
Category
Skill Compromise
Scan Target
mcp
Author
Threat Cloud LLM Analyzer
Response Actions
alertsnapshot