agentic-jujutsu

Warn

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines pre and post lifecycle hooks in its metadata that automatically execute shell commands when files are edited or the skill is activated.
  • Evidence: The hooks section in SKILL.md executes node cli.js pre-edit "$FILE" and node cli.js post-edit "$FILE" "true" from the /workspaces/ruvector/.claude/intelligence directory.
  • [REMOTE_CODE_EXECUTION]: The skill documentation provides instructions to download and execute code from the NPM registry.
  • Evidence: The Installation section in SKILL.md contains the command npx agentic-jujutsu.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external task descriptions and critiques that influence future AI-generated suggestions, creating a vulnerability surface where malicious data could manipulate agent behavior.
  • Ingestion points: The task parameter in jj.startTrajectory(task) and the critique parameter in jj.finalizeTrajectory(score, critique).
  • Boundary markers: None observed in the implementation examples to delimit untrusted data.
  • Capability inventory: The JjWrapper possesses capabilities to execute arbitrary shell commands via jj.execute(), perform version control operations, and manage encrypted trajectories.
  • Sanitization: No explicit validation or sanitization of the task or critique inputs is demonstrated before they are processed by the ReasoningBank intelligence layer.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 18, 2026, 05:38 AM
Security Audit — agent-trust-hub — agentic-jujutsu