Jutsu (術) — Japansese word for technique / skill. Something you learn once and then just use.
Apps of the future are just skills.
A skill is a folder: some markdown describing how it should behave, plus the shell scripts it needs to do the work. Jutsu is the shell that turns that folder into a real app — its own chat surface, its own UI, its own data folder.
Simply Paste a skill URL, hit install, and you have a working 'app'.
That's the whole idea, and it's the whole product.
Here is an entire app. Not a snippet from one — the whole thing:
---
name: gh-stats
description: Ask questions about any GitHub repo and get instant stats cards.
permissions:
network: ["api.github.com", "github.com"]
commands: ["gh", "jq"]
commands:
- id: repo-summary
run: ./scripts/summary.sh {{repo}}
description: Stats summary for a GitHub repo (owner/name)
output: json
---
# gh-stats
Summarize any public GitHub repo using the `gh` CLI.
- Run `repo-summary` with a slug like `facebook/react`.
- Never prompt for auth; if `gh` is missing, report the error card and stop.That's bundled/gh-stats/SKILL.md. Frontmatter declares what the app is and what
it needs. The body is instructions to the model. The output: json line means
"whatever this script prints, show it as a card."
Everything else is optional, and degrades gracefully:
| You write | You get |
|---|---|
Just name + description |
A chat app. No scripts, no prompts, nothing to approve. |
+ permissions |
A manifest, so Jutsu knows what's in bounds before anything runs. |
+ commands |
Quick-action chips. Buttons instead of typing. |
+ ui: a2ui/ |
Your own hand-tuned A2UI surface. |
| Nothing else at all | Jutsu compiles a UI for you on first open — one LLM call reads your markdown and your scripts' --help output, and emits a validated A2UI document. |
That last row is the one that matters. You never write a frontend. Not a
component, not a stylesheet, not a route. You describe what the app does, and the
app gets chips, forms, tables, and result cards. If the compiled UI is wrong,
it's wrong as data — /ui fix make the table sortable regenerates it with an
old-vs-new preview and a Revert button. UI bugs are data fixes, not code fixes.
Because the format is SKILL.md, thousands of skills that already exist work on
day one. Jutsu's extensions are strictly additive: a folder with a name and a
description is a valid app.
npm install
npm run build # build the web UI into web/dist
npm start # daemon on http://localhost:7600Open http://localhost:7600. First run, pick a provider — OpenAI,
Anthropic, any OpenAI-compatible endpoint, Ollama, or Mock — and
paste a key. Mock needs no key and is fully deterministic; it's how the smoke
test runs without a network.
npm run smoke # end-to-end test with the mock provider (throwaway ~/.jutsu)Then install something. bundled/gh-stats is a good first app; the Starter Pack
also ships file-search (ripgrep wrapper), text-transform, and
a2ui-gallery — the last one is a curated A2UI document that exercises the
entire component catalog, and doubles as a look at what an app's surface can be.
Adding a default app is one entry in config/default-apps.json. No code.
Skills & install
- Paste a git URL, local path, or bundled source. Multi-skill repos get an install picker; packs get a pack preview with per-app checkboxes.
- Schema-validated
SKILL.mdfrontmatter, with lenient parsing for real-world skills — unknown keys warn, they don't fail. - Machine-derived capability linter: network, credentials, destructive patterns, fs-writes, each with the offending script line quoted.
- Pack installs are batched but individually consented, and fault-isolated — one dead entry fails alone with its own report card while the rest install.
Runtime
- One chat engine. Opening an app is a persona swap: system prompt + primer, working directory = that app's data folder. No per-app processes, no per-app servers.
- Streaming, tool-calling, session persistence as JSONL in the app's data dir.
- Providers: OpenAI, Anthropic, OpenAI-compatible, Ollama, Mock. Per-app overrides.
UI
- Closed component catalog — Card, Text, TextField, NumberField, Select, Button, Chips, Table, KeyValue, Form — rendered natively. No freeform HTML anywhere in card content; model and user strings render as text, never markup.
- Install-time UI compiler: one LLM call, schema validation, one repair retry, fallback skin on failure. Anything failing validation falls back safely with a notice in the inspector — never a broken card in chat.
update_uilets apps evolve their own surface mid-conversation: a result card updates in place when you ask a follow-up, with no re-render and no state loss.output: jsonon a command hydrates Tables and KeyValue cards automatically. Wrapping an existing CLI is a one-file adapter.
Trust & safety
- Permission cards with Run once / Always allow / Deny, and manifest rules learned from your approvals.
- Supervised / Trusted / Quarantined, recomputed locally. Auto-quarantine with an incident card when a Trusted app reaches outside its manifest.
- Spawn broker with process-group kill, 120 s watchdog, 5 MB output cap, and an
out-of-band
POST /api/killthat works on a hung turn. - Git checkpoint per turn and before destructive commands.
server/ daemon: config, models adapter, install pipeline, broker, chat, a2ui
schemas/ skill.schema.json · pack.schema.json · a2ui.schema.json
bundled/ sample apps (gh-stats, file-search, text-transform, a2ui-gallery)
packs/ founders-pack.json · marketing-pack.json
web/ React SPA (rail + chat spine + inspector), built to web/dist
test/ smoke.mjs — end-to-end with the mock provider
config/ default-apps.json — the starter pack
User state lives in ~/.jutsu/: registry/ (pristine copies), apps/ (live
git-repo data dirs), logs/ (broker event JSONL), config.json.
prd.md— requirements, milestones, acceptance criteria, the full v1 contract and v2 backlog.design.md— the visual language, the layout shell, and the card system.