ralph-loop-init

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill fragment is broadly coherent with its stated purpose of generating and orchestrating a Ralph Loop from a plan, including file generation and autonomous iteration guidance. However, the presence of autonomous execution mode (dangerously-skip-permissions), potential broad file system impact (.ralph directory and generated artifacts), and reliance on an external tool (claude) without explicit safeguards create elevated security risk. The design warrants cautious review and additional safeguards (per-step prompts, explicit allowed actions, audit trails, and runtime restrictions) before deployment in production or security-sensitive environments. Overall assessment: elevated risk but not definitively malicious; treat as suspicious until mitigations are in place.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 09:11 PM
Package URL
pkg:socket/skills-sh/techdufus%2Foh-my-claude%2Fralph-loop-init%2F@7f3e7e0f5dd4d22dc99b153df463bfbbc5f971d1