agentic-jujutsu

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s repo-automation purpose broadly matches its capabilities, but the documented 'embedded jj binary' creates a major install-trust gap. Without verifiable provenance for that executable, the skill is high risk even though no explicit credential theft or exfiltration endpoint is shown.

Confidence: 78%Severity: 74%
Audit Metadata
Analyzed At
Aug 21, 2026, 05:04 AM
Package URL
pkg:socket/skills-sh/i-onlabs%2Fclaude-code-skills%2Fagentic-jujutsu%2F@4dd7884ce1ba59682ff4ccdc1a5eb95a7d36648e0a6000cac18cd0796f2cb789
Security Audit — socket — agentic-jujutsu