ralph-execute
Pass
Audited by Gen Agent Trust Hub on Mar 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agent to perform complex multi-agent orchestration tasks with elevated permissions.\n
- It explicitly instructs the agent to 'Keep all role configs at full permissions (danger-full-access)'.\n
- It utilizes agent spawning capabilities with specific isolation settings ('fork_context = true') to manage 'worker' and 'explorer' roles.\n- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection (Category 8) because it uses repository-hosted files to determine orchestration logic.\n
- Ingestion points: Reads state, policy, and configuration from '.ralph/state/workflow-state.json', '.ralph/state/spec-queue.json', '.ralph/policy/project-policy.md', and 'AGENTS.md'.\n
- Boundary markers: None identified; the skill instructions mandate treating these files as the 'canonical machine state' and 'source of truth'.\n
- Capability inventory: Includes the ability to read and write files within the repository and to spawn and configure sub-agents with full access permissions.\n
- Sanitization: There is no evidence of validation or sanitization for the content of the read files before they are used to influence the agent's workflow and role selection.
Audit Metadata