ralphmode
Warn
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions that explicitly guide the user or agent to bypass or override built-in security permission systems. Key examples include enabling
bypassPermissionsin Claude Code, settingapproval_policy = "never"in Codex CLI, and using the--dangerously-skip-permissionscommand-line flag. - [COMMAND_EXECUTION]: The skill provides shell script templates (e.g.,
ralph-safety-check.sh) and instructions to make them executable viachmod +x. These scripts are intended to be used as system hooks to intercept and validate commands at runtime. - [EXTERNAL_DOWNLOADS]: The documentation references external configuration guidelines and repositories, such as the official Google Gemini GitHub repository, to assist with platform-specific setup.
Audit Metadata