ralph-loop

Fail

Audited by Socket on Apr 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: The skill’s core purpose matches orchestration of coding-agent loops, but its footprint is high-risk because it grants broad autonomous execution to external CLIs and promotes dangerous approval-bypass flags. Install trust is mostly same-org official for OpenCode/Codex/Claude/Goose, lowering malware concern, but Pi provenance is weaker and the overall design is still risky due to delegated autonomy over code, tests, and commits.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Apr 15, 2026, 03:12 PM
Package URL
pkg:socket/skills-sh/addozhang%2Fopenclaw-forge%2Fralph-loop%2F@eb5c5d7099326eb2bc4061c83224e80a66d2a5f6