ralph-claude-code-autonomous-development
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s autonomous-development purpose matches much of its behavior, but the trust boundary is weak: ara.so publishes the skill while installation comes from an unrelated GitHub repo, core setup runs install scripts, uninstall uses curl|bash, and the installed tool receives Anthropic credentials while being granted broad autonomous shell/file capabilities. This is a coherent but high-risk skill with disproportionate install and execution trust concerns rather than confirmed malware.
Confidence: 87%Severity: 79%
Audit Metadata