ralph-wiggum
Warn
Audited by Socket on Apr 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's core purpose is coherent, and its install/data-flow footprint is mostly local and proportionate, with no third-party credential routing or suspicious installer. The main risk is the autonomous development loop itself: repeated command execution, file modification, and optional auto-commit with limited per-action approval, plus possible prompt contamination from persistent progress memory and any downstream harness it invokes.
Confidence: 85%Severity: 56%
Audit Metadata