agentic-jujutsu

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a 'ReasoningBank' self-learning mechanism that allows operation data and critiques from one agent to influence the suggestions provided to other agents.\n
  • Ingestion points: startTrajectory(task) and finalizeTrajectory(score, critique) in SKILL.md ingest external text data into the shared learning model.\n
  • Boundary markers: There are no specified delimiters or instructions to prevent the model from treating embedded commands in critiques as valid future instructions.\n
  • Capability inventory: The jj.execute() method allows for shell command execution based on these AI-generated suggestions, creating a potential vector for cross-agent instruction injection.\n
  • Sanitization: The documentation mentions basic structural validation (length and score range) but lacks semantic filtering to prevent prompt injection from polluting the learning trajectory.\n- [COMMAND_EXECUTION]: The JjWrapper.execute() method provides a direct interface for running shell commands. While demonstrated for git operations, the capability could be misused if the inputs derived from AI suggestions are not properly validated.\n- [EXTERNAL_DOWNLOADS]: The skill's installation instructions recommend using npx agentic-jujutsu, which involves downloading and executing a package from the npm registry at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 06:12 AM
Security Audit — agent-trust-hub — agentic-jujutsu