跳到主要内容
知仓学习社ZHICANG

cron-automation

Audit and create cron jobs with reliability and safety.

执行命令写文件严重 2 · 高危 3notque/vexjoy-agent

它会碰到什么

扫了多少5 个文本文件,36 KB
它会碰到什么执行命令写文件
命中总数5 处
命中统计严重 2 · 高 3 · 中 0 · 低 0
逐条看命中(5 条严重或高危)
  • 严重 references/headless-cron-creator.md:3persistence
    Generate headless Claude Code cron jobs from a task description and schedule. Creates a wrapper script with safety mechanisms (lockfile, budget cap, dry-run def
  • 严重 references/headless-cron-creator.md:145persistence
    Solution: Check `crontab -l` manually. Restore from `~/.claude/crontab-backups/`.
  • references/shell-error-handling.md:156fs-destructive
    rm -rf "$BACKUP_DIR/"    # if BACKUP_DIR is unset, expands to "rm -rf /"
  • references/shell-error-handling.md:160fs-destructive
    **Why this matters**: Without `set -u`, unset variables expand to empty string. `rm -rf "$BACKUP_DIR/"` becomes `rm -rf "/"` when `BACKUP_DIR` is unset. Catastr
  • references/shell-error-handling.md:201fs-destructive
    | `rm -rf /` or similar catastrophic expansion | Undefined variable with `rm -rf "$VAR/"` | Add `set -u` or `${VAR:?msg}` |

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Cron Job Auditor Skill

Static analysis of cron and scheduled job scripts against a 9-point reliability checklist. Produces structured PASS/FAIL/WARN results with severity classification (CRITICAL, HIGH, MEDIUM, LOW) and paste-ready code fixes for every finding. Audits are read-only and pattern-based -- scripts are never executed, because cron scripts may delete data, send emails, or modify production state.

Reference Loading Table

| Signal | Load These Files | Why |

|---|---|---|

| Checking error handling, set -e, pipefail, trap, exit codes | shell-error-handling.md | Routes to the matching deep reference |

| Checking lock files, flock, PID files, concurrent execution | concurrency-and-locks.md | Routes to the matching deep reference |

| Checking logging, timestamps, log rotation, stderr routing | logging-and-rotation.md | Routes to the matching deep reference |

| Creating cron jobs, scheduled tasks, headless agents, wrapper scripts | headless-cron-creator.md | Routes to cron job creation methodology |

Instructions

Phase 1: DISCOVER

Goal: Locate all cron/scheduled scripts to audit.

Step 1: Read repository CLAUDE.md (if present) to understand project conventions before auditing.

Step 2: Identify target scripts

If the user provides specific paths, use those. Otherwise search these directories recursively:

scripts/*.sh, cron/*.sh, jobs/*.sh, bin/*.sh

Also check for scripts referenced in crontab files, Makefiles, or CI configs.

Step 3: Validate targets

For each discovered file:

  • Confirm it exists and is readable
  • Check it has a shell shebang (#!/bin/bash, #!/bin/sh, #!/usr/bin/env bash)
  • Skip non-shell files (Python cron jobs, etc.) with a note -- this skill audits shell scripts only; it cannot replace shellcheck for syntax issues or analyze complex control flow beyond pattern matching

Step 4: Log discovery results

## Scripts Found
1. scripts/daily_backup.sh (bash, 45 lines)
2. cron/cleanup.sh (bash, 22 lines)
3. jobs/sync_data.sh (SKIPPED: Python script)

Gate: At least one auditable shell script identified. Proceed only when gate passes.

Phase 2: AUDIT

Goal: Run every check against every script. Run all 9 checks regardless of script size or apparent simplicity -- small scripts grow, and missing basics cause production incidents.

Step 1: Read each script fully

Read the entire file content. Do not sample or skip sections. If the script sources a common library file (source ... or . ...), read the sourced file too -- patterns provided by sourced libraries count as PASS (with a note indicating the source).

Step 2: Run the 9-point checklist

Use regex pattern matching for reliable, reproducible detection. Verify matches are not inside comments (# ...) before counting them -- when a match appears in a comment or string, note reduced confidence rather than silently accepting it.

| # | Check | Patterns | Severity |

|---|-------|----------|----------|

| 1 | Error handling | set -e, set -o errexit, \|\| exit | CRITICAL |

| 2 | Exit code checking | $?, if [ $? -eq, && ... \|\| | HIGH |

| 3 | Logging with timestamps | >> *.log, $(date), date + | HIGH |

| 4 | Log rotation | find -mtime -delete, logrotate, tail -n | MEDIUM |

| 5 | Working directory | cd "$(dirname", SCRIPT_DIR=, absolute paths | HIGH |

| 6 | PATH environment | PATH=, export PATH, source *env | MEDIUM |

| 7 | Lock file / concurrency | .lock, flock, .pid, lock file check | HIGH |

| 8 | Cleanup on exit | trap ... EXIT, trap ... cleanup, rm -rf *tmp | MEDIUM |

| 9 | Failure notification | mail -s, curl *webhook, notify, alert | LOW |

For each check, record:

  • PASS with line number where pattern found, OR
  • FAIL/WARN with specific recommendation including a paste-ready code snippet (findings without fixes create work without guidance)

Step 3: Calculate score

Score = passed / total_checks * 100

Classify scripts: 90-100% Excellent, 70-89% Good, 50-69% Needs Work, <50% Critical.

Gate: All 9 checks run against every script. No checks skipped. Proceed only when gate passes.

Phase 3: REPORT

Goal: Produce structured, actionable audit output. Do not modify any scripts -- report problems with recommendations only.

Step 1: Format per-script results

CRON JOB AUDIT: scripts/daily_backup.sh
==================================================
  [PASS] Error handling (line 3)
  [PASS] Logging with timestamps (line 12)
  [FAIL] Lock file: No concurrent run prevention
  [WARN] PATH environment: PATH not explicitly set

SCORE: 7/9 (78%) - Good

Step 2: Provide recommendations

Every FAIL and WARN must include a specific code snippet the user can paste. Keep recommendations proportional to the script's scope -- suggest lock files, not monitoring frameworks.

# Recommendation: Add lock file
LOCK_FILE="/tmp/daily_backup.lock"
exec 200>"$LOCK_FILE"
flock -n 200 || { echo "Already running"; exit 0; }
trap "rm -f $LOCK_FILE" EXIT

Step 3: Produce aggregate summary

If auditing multiple scripts:

AGGREGATE SUMMARY
=================
Scripts audited: 4
Average score: 72%
Critical issues: 2 (missing error handling)
Most common gap: Lock files (3/4 scripts missing)

Gate: Every finding has a recommendation. Report is complete. Audit is done.

Error Handling

Error: "No Shell Scripts Found"

Cause: Scripts in unexpected locations, or cron jobs written in Python/Ruby

Solution:

  1. Ask user for explicit paths
  2. Search broader: **/*.sh across the entire repository
  3. Check crontab entries for referenced file paths

Error: "Script Has No Shebang"

Cause: Script relies on default shell interpreter

Solution:

  1. Still audit the script (treat as bash)
  2. Add finding: "Missing shebang line" as MEDIUM severity
  3. Recommend adding #!/bin/bash or #!/usr/bin/env bash

Error: "Regex Produces False Positive"

Cause: Pattern matches in comments, strings, or unrelated context

Solution:

  1. Verify match by reading surrounding lines for context
  2. Check if match is inside a comment (# ...) and exclude
  3. Report the finding but note reduced confidence

Error: "Script Uses Non-Standard Patterns"

Cause: Custom error handling, logging frameworks, or wrapper functions

Solution:

  1. Check if script sources a common library file
  2. Read the sourced file for the missing patterns
  3. If patterns exist in sourced libraries, mark as PASS with note

Reference Loading

| Task type / signal | Load this reference |

|--------------------|---------------------|

| Checking error handling, set -e, pipefail, trap, exit codes | references/shell-error-handling.md |

| Checking lock files, flock, PID files, concurrent execution | references/concurrency-and-locks.md |

| Checking logging, timestamps, log rotation, stderr routing | references/logging-and-rotation.md |

| Creating cron jobs, scheduled tasks, headless agents, wrapper scripts | references/headless-cron-creator.md |

References

Best Practices Reference

#!/bin/bash
set -euo pipefail                              # Error handling
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
cd "$SCRIPT_DIR"                                # Working directory
PATH=/usr/local/bin:/usr/bin:/bin               # Explicit PATH
LOCK="/tmp/$(basename "$0").lock"               # Lock file
exec 200>"$LOCK"
flock -n 200 || { echo "Already running"; exit 0; }
LOG="logs/$(basename "$0" .sh)_$(date +%Y%m%d).log"
exec > >(tee -a "$LOG") 2>&1                   # Logging
echo "$(date): Starting"
trap 'rm -f "$LOCK" /tmp/mytmp_*' EXIT         # Cleanup
find logs -name "*.log" -mtime +30 -delete      # Log rotation

# ... actual work ...

if [ $? -ne 0 ]; then                          # Failure notification
    echo "FAILED" | mail -s "Cron Alert" admin@example.com
fi

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 419
本站分层T2
该仓技能数122
原文件路径skills/infrastructure/cron-automation/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 122 个技能