ralph-loop
Audited by Socket on Sep 19, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the skill is purpose-aligned as an agent-orchestration guide, and the scanner’s exfiltration/injection hits are mostly documentation-context false positives. The main risk is not hidden malware but broad autonomous execution through external coding-agent CLIs, especially when using auto-approval flags that bypass safeguards; this makes it a medium-risk orchestration skill rather than a benign static guide.
The fragment is operational documentation for an autonomous coding-agent loop, not direct malware. It presents meaningful security risk if implemented without sandboxing, least-privilege credentials, command validation, and human review because agents may execute commands, modify files, commit changes, access external services, or run with permission bypasses. No direct evidence of credential theft, exfiltration, persistence, sabotage, or obfuscated malicious code appears in the visible text.