ralph-github-start-loop

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The module is an automation tool that legitimately uses official GitHub and git tooling to implement stories from PRDs, but it embodies a high-impact automation pattern: agent-generated code is committed and pushed without a mandated human review gate. I found no direct evidence of embedded malware, hardcoded credentials, or obfuscated payloads in the provided description. The primary risk is operational: a compromised or buggy agent, or overly-broad gh credentials, can cause significant, hard-to-detect repository changes and data exposure. Recommendations before use: restrict gh token scopes, enable branch protections and mandatory PR reviews, require a human approval step or dry-run diff/review, run in least-privileged accounts, and audit agent outputs before push.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:36 AM
Package URL
pkg:socket/skills-sh/richtabor%2Fagent-skills%2Fralph-github-start-loop%2F@67bb34dabe95651d60304cd34e1a97454a1ecaf7