ralph-prd

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core purpose is coherent, but its footprint is high-risk because it enables autonomous project modification through a loop runner that explicitly uses --dangerously-skip-permissions. I see no clear credential-harvesting or malicious exfiltration path in the provided text, so this is better classified as a dangerous autonomous-development skill than confirmed malware.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 26, 2026, 10:57 AM
Package URL
pkg:socket/skills-sh/joaquimscosta%2Farkhe-claude-plugins%2Fralph-prd%2F@4d6ea4edc52699d7e1b141f32b3581bb1f62ad27