ralph

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s looping and DoD-verification behavior matches its stated purpose, but it relies on an unverified external CLI and grants broad autonomous execution with persistent prompt storage and subagent recursion. I found no confirmed credential theft or overt exfiltration, so this is better classified as high-risk/vulnerable rather than malware.

Confidence: 81%Severity: 78%
Audit Metadata
Analyzed At
Apr 8, 2026, 11:02 AM
Package URL
pkg:socket/skills-sh/team-attention%2Fhoyeon%2Fralph%2F@ff1b3d16a8f0f8fe616d223dae272682be5dd1df