ralph
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core behavior matches its stated purpose, but that purpose is a high-autonomy orchestration loop with background execution, delegated agents, and optional external URL processing. Install provenance appears reasonably consistent with the official Agent Skills ecosystem, so this is not confirmed malware, but the autonomy and external-content-to-execution pattern make it a materially risky skill.
Confidence: 85%Severity: 69%
Audit Metadata