replikator-ralph
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill architecture is built on defensive principles. It uses a structured 'Ralph loop' that requires six independent approvals (three lenses across two consecutive teams) before any task is considered complete. This multi-layered verification is a significant security feature that mitigates risks of errors or malicious logic in generated artifacts.
- [COMMAND_EXECUTION]: The skill coordinates work across multiple delegated roles ('replikator-executor', 'replikator-verifier') which involves modifying project files and running verification checks. These operations are constrained by a strict 'artifact-state invariant' protocol that uses reproducible identifiers to ensure that all verification is performed against an identical, stable state.
- [PROMPT_INJECTION]: The verification protocol explicitly includes an 'Adversarial-testing lens' designed to derive and run failure and misuse cases. This proactively identifies potential security flaws or prompt injection attempts in the work produced by earlier stages of the pipeline.
Audit Metadata