setup-ralph

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
steps/step-00-init.md

The step itself is an orchestration/initializer and contains no explicit malicious code in the supplied fragment. However, it requires executing a bundled setup.sh script with user-controlled arguments and writing files, which is a common supply-chain risk. Treat this as a moderate security risk: safe only if the setup.sh contents are reviewed or verified and if user inputs (feature_name, project_path) are strictly validated/sanitized and the script is executed with least privilege or in a sandbox. Do not run setup.sh blindly in privileged or unattended environments without integrity checks.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 17, 2026, 05:51 AM
Package URL
pkg:socket/skills-sh/melvynx%2Faiblueprint%2Fsetup-ralph%2F@8cb475800a92ab22e87723d03d42c3e65ceaf6dc