ralph-orchestrator

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its stated purpose as an autonomous coding orchestrator, but it normalizes high-risk behavior: disabled permission checks, unattended background execution, broad shell/git/write authority, and external model/data flows. This looks more like an intentionally powerful automation skill than malware, yet its operational footprint is risky enough to classify as suspicious/high-risk rather than benign.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Mar 19, 2026, 09:44 AM
Package URL
pkg:socket/skills-sh/yoloshii%2Fralph-orchestrator-skill%2Fralph-orchestrator%2F@a966067a54d67c28a243e4bc656b57dde617ee6a