ralph-init

Warn

Audited by Socket on May 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core local setup behavior is coherent, but the skill expands into enabling autonomous git/PR actions, suggests disabling sandbox protections for discovery, executes an unseen bootstrap script, and instructs transitive installation through a third-party skills CLI unrelated to Anthropic's native skill path. This is not confirmed malware, but its trust footprint is broader than a simple one-time project initializer.

Confidence: 86%Severity: 71%
Audit Metadata
Analyzed At
May 10, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/Olunuga%2Fralph-loop%2Fralph-init%2F@aaab493a26dd8a4c71d3613afe65a64a733e2c2d