Appearance
Why It Matters
Plugin hooks run automatically in installed tooling. Cron mutation from those hooks creates recurring persistence on the host.
What Triggers
SEC658 matches plugin hook command strings that mutate cron through crontab or write cron persistence files such as /etc/crontab, /etc/cron*, or /var/spool/cron.
False Positives
Provisioning-style plugins may do this intentionally, but it should remain explicit and reviewed.
Remediation
Remove cron persistence from the plugin hook and keep scheduled-task installation out of ordinary shared plugins.