ralph-claude-code-autonomous-development

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s autonomous-development purpose matches much of its behavior, but the trust boundary is weak: ara.so publishes the skill while installation comes from an unrelated GitHub repo, core setup runs install scripts, uninstall uses curl|bash, and the installed tool receives Anthropic credentials while being granted broad autonomous shell/file capabilities. This is a coherent but high-risk skill with disproportionate install and execution trust concerns rather than confirmed malware.

Confidence: 87%Severity: 79%
Audit Metadata
Analyzed At
May 17, 2026, 10:06 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Fclaude-code-skills%2Fralph-claude-code-autonomous-development%2F@9dc55a647db4c439accc9445ba4951562ff7351f
Security Audit — socket — ralph-claude-code-autonomous-development