ralph

Warn

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches extensions, plugins, and skill components from GitHub repositories including github.com/Q00/ouroboros and github.com/akillness/oh-my-skills.
  • [COMMAND_EXECUTION]: Includes a shell script (setup-codex-hook.sh) that executes bash and python commands to modify the user's local environment and agent configuration.
  • [DATA_EXFILTRATION]: Accesses and modifies sensitive local configuration files, specifically ~/.codex/config.toml, to inject custom instructions and contract logic.
  • [PROMPT_INJECTION]: Contains instructions that attempt to override standard agent behavior and interaction patterns, such as the 'Ralph' loop which commands the agent to persist autonomously ('the boulder never stops') until a specific verification goal is achieved, potentially bypassing manual user oversight.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 29, 2026, 02:29 AM