ralph-kage-bunshin-loop

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core local worker-loop behavior is coherent, but the skill expands its trust boundary by delegating to multiple unspecified external skills and by processing untrusted web content while retaining write/exec powers. Data flow is mostly local and loopback, so this is not confirmed malware, but it is a medium-high risk orchestration skill with transitive trust and prompt-injection exposure.

Confidence: 84%Severity: 69%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:36 PM
Package URL
pkg:socket/skills-sh/dididy%2Fralph-kage-bunshin%2Fralph-kage-bunshin-loop%2F@d6a3615c4b62a509a37a04e6a658575aeb7b3d32