t3-code-continue-thread
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes historical conversation data from past threads which could contain malicious instructions intended to influence the subagent or current agent behavior.
- Ingestion points: The
scripts/find_thread.pyscript reads theitem_jsoncolumn from thethread_itemstable inthread_history_1.sqlite. - Boundary markers: No delimiters or "ignore embedded instructions" warnings are added to the extracted conversation text.
- Capability inventory: The skill executes shell commands via
gitand has file-write capabilities through the referencedhandoffskill. - Sanitization: Input is truncated to a character limit but not otherwise sanitized or escaped.
- [COMMAND_EXECUTION]: The script
scripts/find_thread.pyexecutes localgitbinaries to verify worktrees and branches. - Evidence: Multiple calls to
subprocess.check_outputare used to run commands likegit rev-parseandgit worktree list. - Mitigation: The script passes arguments as a list rather than a shell string, mitigating standard shell injection vulnerabilities.
- [DATA_EXFILTRATION]: The skill reads sensitive conversation history and local file paths from SQLite databases located in the user's
${CODEX_HOME}directory. - Evidence: The script accesses
state_5.sqlite,thread_history_1.sqlite, andgoals_1.sqliteto extract metadata and full message history.
Audit Metadata