ralph-loop

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The local compat engine is coherent and low-risk, but the optional `open` engine introduces medium trust and data-flow risk by delegating prompts and loop execution to a third-party CLI from a different publisher without install verification or clear endpoint/credential guidance. This is not confirmed malware, but the skill’s external backend footprint is only partially justified and insufficiently documented.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 11, 2026, 02:51 PM
Package URL
pkg:socket/skills-sh/foryourhealth111-pixel%2FVibe-Skills%2Fralph-loop%2F@0f802782be9a42cda5aa94a093f4cab8df0a8f3d