ralph-lisa-loop

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is coherently aligned with its stated purpose of an automated planning/implementation loop with Codex as reviewer. It introduces local environment configuration changes (hook installation, MCP setup) and a potential npm-based tool installation, which are legitimate in a developer workflow but introduce risk if executed without explicit user consent or in untrusted environments. Overall, the code footprint is benign in intent but carries medium configurational risk due to modifying user settings and installing external tooling. No credential reading or exfiltration is evident in this fragment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 06:30 PM
Package URL
pkg:socket/skills-sh/basecamp%2Fskills%2Fralph-lisa-loop%2F@f36da085bd8a43ad78d76b71fbc8a4ba210adea5