skills/akillness/oh-my-gods/ralph/Gen Agent Trust Hub

ralph

Warn

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill's core functionality, 'Ralph mode,' is explicitly designed to bypass standard interaction limits and halting behavior. By instructing the agent that 'the boulder never stops' and to 'stop prompting,' it overrides normal conversational constraints and user control in favor of persistent autonomous operation.
  • [REMOTE_CODE_EXECUTION]: The 'ooo ralph' and 'ooo evolve' commands automate a cycle of command execution via the 'Bash' tool and iterative evaluation. This autonomous loop executes potentially arbitrary shell commands based on the agent's own previous outputs, significantly expanding the attack surface for unintended operations.
  • [EXTERNAL_DOWNLOADS]: The skill directs users to fetch and execute code from external, non-whitelisted sources, including 'github.com/Q00/ouroboros' and 'github.com/supercent-io/skills-template' via 'npx' and platform-specific extension managers.
  • [COMMAND_EXECUTION]: The provided 'setup-codex-hook.sh' script performs automated modifications to the user's environment by editing the '~/.codex/config.toml' file and creating new prompt templates. These changes persist instructions that alter the base behavior of the Codex CLI.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 23, 2026, 08:26 AM