ralph

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Benign in intent and footprint given the described purpose, but with operational risks related to autonomous looping and dependency installation. The momentum of actions across turns is coherent with the stated goal of iterative refinement, and there are no obvious malicious data flows or credential handling in this fragment. Monitor for potential runaway iteration, ensure extension sources are trusted, and enforce strict sandboxing with untrusted code. Recommend adding explicit controls: pin extension versions, SBOM generation, timeout/watchdog for iterations, and mandatory sandboxed execution with restricted file system access.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/supercent-io%2Fskills-template%2Fralph%2F@901fa43f040cc55022a45649a658e2ebe1237134