ralph-kage-bunshin-watcher
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose as an orchestrator matches its tmux/task-management behavior, but it grants unusually strong autonomous control by spawning many Claude sessions with `--dangerously-skip-permissions`, reacting to unauthenticated local messages, and modifying project state without per-step approval. No clear malicious exfiltration endpoint is shown, so this is high-risk automation rather than confirmed malware.
Confidence: 87%Severity: 79%
Audit Metadata