agentic-jujutsu
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines
preandpostlifecycle hooks in its metadata that automatically execute shell commands when files are edited or the skill is activated. - Evidence: The
hookssection inSKILL.mdexecutesnode cli.js pre-edit "$FILE"andnode cli.js post-edit "$FILE" "true"from the/workspaces/ruvector/.claude/intelligencedirectory. - [REMOTE_CODE_EXECUTION]: The skill documentation provides instructions to download and execute code from the NPM registry.
- Evidence: The Installation section in
SKILL.mdcontains the commandnpx agentic-jujutsu. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external task descriptions and critiques that influence future AI-generated suggestions, creating a vulnerability surface where malicious data could manipulate agent behavior.
- Ingestion points: The
taskparameter injj.startTrajectory(task)and thecritiqueparameter injj.finalizeTrajectory(score, critique). - Boundary markers: None observed in the implementation examples to delimit untrusted data.
- Capability inventory: The
JjWrapperpossesses capabilities to execute arbitrary shell commands viajj.execute(), perform version control operations, and manage encrypted trajectories. - Sanitization: No explicit validation or sanitization of the
taskorcritiqueinputs is demonstrated before they are processed by the ReasoningBank intelligence layer.
Audit Metadata