ralph
Warn
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches and installs extensions and plugins from unverified external GitHub repositories (
github.com/Q00/ouroborosandgithub.com/supercent-io/skills-template).- [COMMAND_EXECUTION]: A setup script (setup-codex-hook.sh) uses Python to modify the user's local configuration file for the Codex CLI (~/.codex/config.toml) and establishes persistent hooks that execute scripts automatically during agent sessions.- [REMOTE_CODE_EXECUTION]: Installation procedures for Claude, Codex, and Gemini platforms involve executing unverified code from remote sources vianpx,claude plugin install, andgemini extensions installcommands.- [DATA_EXFILTRATION]: The skill requiresWebFetchpermissions and implements a 'Consensus' verification phase that may involve transmitting data to external 'Frontier' models or APIs.- [PROMPT_INJECTION]: The skill exhibits an indirect injection surface by processing untrusted project requirements and specification seeds through persistent loops with access toBashandWritetools (Ingestion: User-provided topics and YAML seeds in SKILL.md; Boundary markers: Absent; Capability inventory: Bash, Write, and WebFetch tools used in Ouroboros loops; Sanitization: No input validation found in setup or logic files).
Audit Metadata