ralph

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The described skill is coherent with its stated purpose (scaffolding and running an autonomous coding loop). The content does not contain obvious malicious code, hard-coded credentials, or obfuscated constructs. However, the workflow copies, chmods, and executes a local shell script (ralph-loop.sh) whose contents are not provided — this is a material supply-chain/execution risk. Treat templetes/ralph-loop.sh as untrusted until inspected. Run initial executions in an isolated environment and verify template integrity. The package is not demonstrably malicious, but running the opaque script without review presents a moderate security risk.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:19 PM
Package URL
pkg:socket/skills-sh/kv0906%2Fcc-skills%2Fralph%2F@2065c0e252a999e57f762195f6eff5262950e2a1