ralph
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill implements a legitimate workflow for project management and task verification.
- [DATA_EXFILTRATION]: The skill interacts with local project files such as
.omp/prd.jsonand.omp/state/ralph-progress.json. This access is restricted to the skill's state management and requirements tracking, with no evidence of sensitive data exposure or network exfiltration. - [COMMAND_EXECUTION]: While the skill description mentions running tests for verification, these are part of a standard development workflow. The skill itself does not provide arbitrary shell command execution capabilities.
- [PROMPT_INJECTION]: The skill uses structured delegation via sub-agents. It does not contain instructions that attempt to bypass safety filters or override the base agent's system prompt.
Audit Metadata