ralph-loop
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements an iterative loop mechanism where user-provided task prompts are stored in a local scratchpad file (
.cursor/ralph/scratchpad.md) and automatically fed back to the agent at the end of every turn. This creates an attack surface where instructions embedded within the user's task or generated content could influence the agent's behavior in subsequent iterations. - Ingestion points: The user's task prompt and completion promise are captured in
SKILL.mdand written to the state file. - Boundary markers: The state file uses YAML frontmatter to separate metadata from the prompt, but there are no explicit boundary markers or instructions to the agent to treat the re-injected prompt as untrusted data.
- Capability inventory: The skill utilizes file system tools to create directories and write the iterative state to disk.
- Sanitization: The skill does not perform sanitization, filtering, or escaping on the user's task prompt before it is iteratively re-injected into the session context.
Audit Metadata