agentic-jujutsu
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a 'ReasoningBank' self-learning mechanism that allows operation data and critiques from one agent to influence the suggestions provided to other agents.\n
- Ingestion points:
startTrajectory(task)andfinalizeTrajectory(score, critique)inSKILL.mdingest external text data into the shared learning model.\n - Boundary markers: There are no specified delimiters or instructions to prevent the model from treating embedded commands in critiques as valid future instructions.\n
- Capability inventory: The
jj.execute()method allows for shell command execution based on these AI-generated suggestions, creating a potential vector for cross-agent instruction injection.\n - Sanitization: The documentation mentions basic structural validation (length and score range) but lacks semantic filtering to prevent prompt injection from polluting the learning trajectory.\n- [COMMAND_EXECUTION]: The
JjWrapper.execute()method provides a direct interface for running shell commands. While demonstrated forgitoperations, the capability could be misused if the inputs derived from AI suggestions are not properly validated.\n- [EXTERNAL_DOWNLOADS]: The skill's installation instructions recommend usingnpx agentic-jujutsu, which involves downloading and executing a package from the npm registry at runtime.
Audit Metadata