ralph
Warn
Audited by Socket on Mar 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's stated purpose (specification-first, Socratic interviewing, and persistent, convergent loop) is coherent with its multi-platform orchestration and iterative design. However, its footprint includes dynamic installation of third-party binaries/plugins, cross-platform hook integrations, persistent state management, and autonomous execution loops which create significant supply-chain and data-flow risk. The combination of external plugin installs, hook-based execution, and persistent autonomous iteration warrants caution and closer scrutiny before deployment in any security-conscious environment.
Confidence: 62%Severity: 68%
Audit Metadata