ralph
Warn
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches extensions, plugins, and skill components from GitHub repositories including
github.com/Q00/ouroborosandgithub.com/akillness/oh-my-skills. - [COMMAND_EXECUTION]: Includes a shell script (
setup-codex-hook.sh) that executes bash and python commands to modify the user's local environment and agent configuration. - [DATA_EXFILTRATION]: Accesses and modifies sensitive local configuration files, specifically
~/.codex/config.toml, to inject custom instructions and contract logic. - [PROMPT_INJECTION]: Contains instructions that attempt to override standard agent behavior and interaction patterns, such as the 'Ralph' loop which commands the agent to persist autonomously ('the boulder never stops') until a specific verification goal is achieved, potentially bypassing manual user oversight.
Audit Metadata