cujo
Skip to content
Contents

The four checks

Tests, probes, a smoke boot and dependency detonation, and the four sensors watching all of them.

Four checks

Each runs as its own subagent with fresh context: the check’s instructions and the sandbox, no shared history, and no sight of any other check’s report. Only a JSON report comes back.

These are the sandbox review’s. A diff review (mode: diff) runs none of them: its run page says so in their place, its findings are the model’s reading of the diff, and the hard rules below have nothing to fire on.
CheckWhat it does
testsRuns the repository’s suite on base and on head, in the same box, like for like. Reports each test’s status on both sides and derives the set that passes on base and fails on head — which is the single most useful thing a reviewer can be told.
probesReads the diff, writes small scripts that call the changed functions with inputs it chooses, and runs them. The expectation is stated before the script runs, so the report records a prediction and its outcome rather than a description of what happened.
smokeBoots the app, hits the configured or inferred endpoints, stops it — on head, then on base. Reports each endpoint’s status on both sides, plus the log tail.
detonationRuns only when a dependency manifest changed. Diffs the manifest to the specifiers that were added or version-bumped, then installs each one on its own into a fresh environment and records the hosts it contacted, the files it touched and the processes it spawned. A version bump counts: a compromised release is a real attack, and the new version runs new install code.
No test suite and none named in .cujo.yml means one warn and a stop. No checks are spawned at all — running probes against code whose own suite cannot be found is a measurement of nothing.

What was watching

Four sensors, shared by every check. Every report says which of them were armed, so “nothing was observed” and “nothing could have been observed” never read alike.

SensorSeesBlind to
proxyHost, port and byte count for every connection made through it — pip, npm, cargo, go, curl, the common HTTP libraries.Payloads: there is no TLS interception. And a process that opens a socket directly rather than honouring the proxy variables.
decoyA seeded credentials file that nothing legitimate has any reason to open. Any read of it is recorded.Nothing, where the kernel provides file-watch events.
auditInside Python: file opens, socket connects, subprocesses. It rides into every Python child, including pip running a package’s setup.py.Anything that is not Python. Reported as unarmed, not as clean.
fs_diffEverything created or modified outside the workspace, and anything under a sensitive path, by content hash where a silent edit is the attack.Never off, only capped. The report names the cap when one cut the evidence short.

An unarmed proxy or decoy earns a warn of its own, never a critical: it says the evidence was thin, not that the code did anything.

Egress, and what makes a host unknown

Every host contacted is classified once, against two lists: the package indexes Cujo knows about — PyPI, npm, crates.io, the Go module proxy, RubyGems, GitHub’s own download hosts — and whatever the repository named in allow_hosts. Anything else is unknown.

  • Unknown egress during detonation is critical, and it is a hard rule. An install that phones home is the supply-chain attack this check exists to catch.
  • Unknown egress during any other check is a warn. A test suite reaching a host the allowlist does not name is worth a look, and painting it in the same red would be the page making an accusation the reviewer did not.