ralph-wiggum-loop

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s overall purpose is coherent for a workflow engine, but its footprint is broader than well-scoped guidance. The main concerns are unverifiable plugin/package provenance, transitive code execution through plugin registries, and broad access to secrets/config plus outbound integrations. No confirmed credential theft or overtly malicious endpoint is shown, so this is high vulnerability rather than confirmed malware.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
Apr 8, 2026, 02:47 PM
Package URL
pkg:socket/skills-sh/wojons%2Fskills%2Fralph-wiggum-loop%2F@19d705e40140a352cb6bf4200145fbf2ef8b57dc