ralph-loop
Pass
Audited by Gen Agent Trust Hub on Feb 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill facilitates an iterative development loop, known as a 'Ralph Loop', by saving task state to a local file in the '.cursor/ralph/' directory. This is an intended architectural feature for development agents using the Cursor IDE. No malicious patterns such as credential theft, unauthorized data exfiltration, or remote code execution from untrusted sources were identified. The workflow incorporates safety guardrails, including iteration limits ('max_iterations') and clear state boundaries using YAML frontmatter. Potential indirect prompt injection surfaces are mitigated by the primary purpose of the tool and the use of explicit delimiters.
Audit Metadata