ralph-kage-bunshin-watcher

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose as an orchestrator matches its tmux/task-management behavior, but it grants unusually strong autonomous control by spawning many Claude sessions with `--dangerously-skip-permissions`, reacting to unauthenticated local messages, and modifying project state without per-step approval. No clear malicious exfiltration endpoint is shown, so this is high-risk automation rather than confirmed malware.

Confidence: 87%Severity: 79%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:36 PM
Package URL
pkg:socket/skills-sh/dididy%2Fralph-kage-bunshin%2Fralph-kage-bunshin-watcher%2F@944e730f2b9d1d281b1965d9d243706099897315