t3-code-continue-thread

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes historical conversation data from past threads which could contain malicious instructions intended to influence the subagent or current agent behavior.
  • Ingestion points: The scripts/find_thread.py script reads the item_json column from the thread_items table in thread_history_1.sqlite.
  • Boundary markers: No delimiters or "ignore embedded instructions" warnings are added to the extracted conversation text.
  • Capability inventory: The skill executes shell commands via git and has file-write capabilities through the referenced handoff skill.
  • Sanitization: Input is truncated to a character limit but not otherwise sanitized or escaped.
  • [COMMAND_EXECUTION]: The script scripts/find_thread.py executes local git binaries to verify worktrees and branches.
  • Evidence: Multiple calls to subprocess.check_output are used to run commands like git rev-parse and git worktree list.
  • Mitigation: The script passes arguments as a list rather than a shell string, mitigating standard shell injection vulnerabilities.
  • [DATA_EXFILTRATION]: The skill reads sensitive conversation history and local file paths from SQLite databases located in the user's ${CODEX_HOME} directory.
  • Evidence: The script accesses state_5.sqlite, thread_history_1.sqlite, and goals_1.sqlite to extract metadata and full message history.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 08:49 AM
Security Audit — agent-trust-hub — t3-code-continue-thread