ralph
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileThe skill presents a coherent overarching purpose for specification-first AI development with an ambitious, multi-platform loop (Ralph) that persists until verification but introduces notable risks around autonomous long-running actions, cross-platform plugin/hook installations, and complex data flows. While many components align with the stated goal of iterative refinement, the combination of persistent autonomy, unverifiable third-party plugin usage, and multi-platform execution pathways creates a medium-to-high risk profile. Data flows and external dependencies should be tightly scoped, with explicit per-step user approvals for long-running actions and strict, authenticated plugin provenance checks to reduce supply-chain/autonomy risks.