Back to skill

Security audit

Monitored Ralph Loop

Security checks for vulnerabilities and agentic risk

Overview

This skill is an autonomous coding loop helper, but it includes high-impact defaults and optional setup steps that can run agents unattended with reduced safeguards.

Review this carefully before installing or running. Use it only in a disposable branch, container, VM, or otherwise constrained workspace. Do not run the documented systemd service or swap/fstab commands unless you intentionally want host-level persistent changes and know how to undo them. For Claude, set safe RALPH_FLAGS explicitly rather than accepting the default permission-bypass behavior, and review every commit before pushing or merging.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
README.md:167
Finding

Persistent Autonomous AI Loop Installed as a System Service

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 167–187
Vulnerability Type: System persistence through a boot-enabled systemd service
Risk Level: Critical

Vulnerable Code

bash
# Create service file
sudo tee /etc/systemd/system/ralph-loop.service << 'EOF'
[Unit]
Description=Ralph AI Loop
After=network.target

[Service]
Type=simple
User=YOUR_USER
WorkingDirectory=/path/to/project
ExecStart=/path/to/ralph.sh 50
Restart=on-failure
RestartSec=30
Environment=RALPH_CLI=codex

[Install]
WantedBy=multi-user.target
EOF

sudo systemctl daemon-reload
sudo systemctl enable ralph-loop
sudo systemctl start ralph-loop

Technical Analysis

The documentation instructs users to create a root-owned systemd unit, enable it at boot, and automatically restart it after failures. The service executes an autonomous AI coding loop that reads mutable project instructions and may modify code, run project commands, and commit changes.

Installing a system-wide boot service is not required for the Skill’s core declared purpose of generating and running Ralph loop scripts. A manually launched process, user-scoped transient unit, terminal multiplexer, or container would provide long-running operation without modifying global startup configuration.

Although User=YOUR_USER means the loop should run as the configured non-root account, creating and enabling the service requires root privileges. The resulting process survives shell termination and host reboot, removing the normal interactive boundary associated with starting each run.

Attack Path

  1. A user follows the documented setup using sudo.
  2. A root-owned service definition is written to /etc/systemd/system/ralph-loop.service.
  3. systemctl enable registers the loop to start during future boots.
  4. The service launches ralph.sh, which repeatedly starts an AI coding agent.
  5. The agent consumes mutable project files such as PROMPT.md, AGENTS.md, specifications, and the implementation ...[truncated 1097 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove system-wide boot persistence instructions from the standard workflow.
  • Do not recommend systemctl enable for an autonomous coding agent.
  • If restart support is essential, use an explicitly opt-in user-scoped service under ~/.config/systemd/user/.
  • Prefer a transient unit such as systemd-run --user without boot enablement.
  • Require explicit confirmation before every new loop run.
  • Run the agent inside a container or VM with only the intended project directory mounted.
  • Apply systemd hardening where supported, including:
    • NoNewPrivileges=true
    • PrivateTmp=true
    • ProtectSystem=strict
    • ProtectHome=read-only
    • ReadWritePaths=/path/to/project
    • RestrictSUIDSGID=true
    • MemoryMax=...
    • CPUQuota=...
    • RuntimeMaxSec=...
  • Use an absolute, administrator-reviewed script path and ensure it is not writable by less-trusted users.
  • Document removal and rollback commands for any service that users install.
  • Avoid automatic restart unless a bounded retry count or rate limit is enforced.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/ralph.sh:11
Finding

Claude Code Runs with Permission Checks Disabled by Default

Content
View full analysis

Vulnerability Details

File Location: scripts/ralph.sh, lines 11–18
Vulnerability Type: Automatic bypass of interactive permission controls
Risk Level: High

Vulnerable Code

bash
# CLI-specific default flags
if [[ -z "${RALPH_FLAGS:-}" ]]; then
  case "${CLI}" in
    codex)  CLI_FLAGS="-s workspace-write" ;;
    claude) CLI_FLAGS="--dangerously-skip-permissions" ;;
    *)      CLI_FLAGS="" ;;
  esac
else
  CLI_FLAGS="${RALPH_FLAGS}"
fi

The flag is subsequently used when launching Claude:

bash
claude)
  CMD="claude --print $CLI_FLAGS"
  ;;

Technical Analysis

When RALPH_CLI=claude is selected and RALPH_FLAGS is not explicitly set, the script automatically adds --dangerously-skip-permissions. This disables Claude Code’s normal permission prompts without requiring a separate, explicit decision by the user.

The script does not verify that it is running in a container, VM, disposable account, or restricted filesystem. A warning elsewhere in the documentation does not enforce a security boundary. Because the agent reads mutable repository files and is intended to run commands and modify code autonomously, disabling permission checks substantially increases the effect of malicious or compromised project instructions.

This exceeds minimum privilege: autonomous operation can instead use ordinary permission prompts, a restricted sandbox, or a narrowly scoped tool policy.

Attack Path

  1. A user selects Claude by setting RALPH_CLI=claude.
  2. The user does not set RALPH_FLAGS.
  3. The script silently supplies --dangerously-skip-permissions.
  4. Each loop iteration loads instructions and state from mutable project files.
  5. An attacker who can influence repository content places unsafe instructions in a file consumed by the agent.
  6. Claude acts on those instructions without its normal interactive permission checks.
  7. If the loop is also run through the documented systemd service, the unsafe behavior may recur unatt ...[truncated 680 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove --dangerously-skip-permissions from the default Claude configuration.
  • Require users to opt in explicitly through RALPH_FLAGS.
  • Reject permission-bypass flags unless a dedicated unsafe mode is separately enabled.
  • Display the fully expanded command and require interactive confirmation before using any bypass flag.
  • Verify sandboxing before permitting bypass mode, rather than relying solely on documentation.
  • Run the agent as a dedicated low-privilege account with access limited to the intended project.
  • Use a container or VM with:
    • No host credential mounts.
    • A read-only home directory.
    • Only the target workspace writable.
    • Restricted network access.
    • CPU, memory, process, and runtime limits.
  • Consider allowlisting safe tools and commands instead of globally disabling approvals.
  • Refuse to run unattended permission-bypass mode from a boot-enabled service.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
README.md:156
Finding

Optional Setup Permanently Modifies Global Swap and Boot Configuration

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 156–158
Vulnerability Type: Unnecessary privileged and persistent host modification
Risk Level: Medium

Vulnerable Code

bash
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

Technical Analysis

The documentation recommends creating a four-gigabyte swap file using root privileges and appending a persistent entry to /etc/fstab. This changes global host state and boot configuration for the optional purpose of improving memory availability for AI agents.

The modification is outside the minimum privileges needed to generate or run a project-local loop. The command appends unconditionally and does not check whether /swapfile already exists, whether swap is already configured, whether sufficient disk capacity is available, or whether an identical /etc/fstab entry already exists.

This is not demonstrated as intentionally malicious code, but it is an unnecessarily privileged and persistent operational recommendation.

Attack Path

  1. A user experiencing or anticipating memory pressure follows the documentation.
  2. The commands allocate a large root-level file and activate it as swap.
  3. An entry is appended to /etc/fstab, making the change survive reboot.
  4. Repeated execution can add duplicate configuration entries.
  5. On a constrained or specially configured host, the disk allocation or boot-time configuration can cause operational problems.

Impact Assessment

The commands require root authority and affect the whole host rather than only the project. Potential consequences include:

  • Permanent consumption of approximately four gigabytes of disk space.
  • Persistent modification of boot configuration.
  • Duplicate /etc/fstab entries after repeated execution.
  • Unexpected swap behavior on encrypted, managed, or storage-constrained systems.
  • Host ins ...[truncated 310 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove host-level swap setup from the primary Skill workflow.
  • Prefer recommending a VM or container with an administrator-defined memory limit and swap policy.
  • State clearly that swap configuration is an optional host-administration task, not a Skill prerequisite.
  • Require an administrator to review platform-specific implications before changing /etc/fstab.
  • Check whether swap is already available before creating a new file.
  • Check available disk capacity and filesystem compatibility.
  • Use an idempotent update that does not append duplicate entries.
  • Include complete rollback instructions covering swapoff, /etc/fstab cleanup, and file removal.
  • Avoid modifying global boot configuration from copy-and-paste project setup instructions.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (36)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · README.md (reported line 157)May include surrounding context.

bash
# Add swap if needed
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · README.md (reported line 158)May include surrounding context.

Add swap if needed

sudo fallocate -l 4G /swapfile sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

text

## Auto-Restart with systemd

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 196)May include surrounding context.

md
- Run in a dedicated branch
- Use a sandbox for untrusted code
- Keep `git reset --hard` ready
- Review commits before pushing

## Credits

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 322)May include surrounding context.

md
- Run in a dedicated branch
- Use a sandbox for untrusted code
- Keep `git reset --hard` ready
- Review commits before pushing

## Credits

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill’s declared purpose is to generate copy-paste scripts, but the content materially expands into operational guidance for running autonomous coding loops, invoking external CLIs, modifying repositories, committing changes, and sending notifications. This mismatch is dangerous because users or orchestration systems may grant it broader trust or permissions than intended, enabling code execution and repository mutation under a narrower-looking description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

For Claude, the script defaults to '--dangerously-skip-permissions', which removes an important safety control without necessity being established by the skill's stated purpose. In a loop that repeatedly prompts an agent to modify a repository and run commands, bypassing permission checks materially increases the chance of destructive file changes, secret access, or unintended command execution.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/ralph.sh (reported line 165)May include surrounding context.

sh
touch AGENTS.md "$PLAN_FILE" 2>/dev/null || true

# Clear any stale pending notification from previous run
[[ -f "$NOTIFY_FILE" ]] && rm -f "$NOTIFY_FILE"

echo -e "${BLUE}🐺 Ralph Loop starting${NC}"
echo -e "   CLI: $CLI $CLI_FLAGS"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 156)May include surrounding context.

bash
# Add swap if needed
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 157)May include surrounding context.

bash
# Add swap if needed
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 158)May include surrounding context.

bash
# Add swap if needed
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 167)May include surrounding context.

bash
# Add swap if needed
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 185)May include surrounding context.

bash
# Add swap if needed
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 187)May include surrounding context.

bash
# Add swap if needed
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 157)May include surrounding context.

bash
# Add swap if needed
sudo fallocate -l 4G /swapfile
sudo chmod 600 /swapfile && sudo mkswap /swapfile && sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The section explicitly encourages auto-restart with systemd for long-running loops, which normalizes persistence for an autonomous agent process. In this skill context, persistence is more dangerous because the loop is intended to continue making changes over time and may operate with elevated autonomy or weak review controls.

Content

Scanner excerpt · README.md (reported line 166)May include surrounding context.

For long-running loops, use systemd to auto-restart on crashes:

bash
# Create service file
sudo tee /etc/systemd/system/ralph-loop.service << 'EOF'
[Unit]
Description=Ralph AI Loop

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

sudo systemctl enable ralph-loop configures the loop to start automatically on boot, creating persistence for an autonomous coding agent. Even though the intent appears operational rather than malicious, persistence raises the risk of unattended execution, recurring unsafe actions, and harder-to-notice failures or misuse.

Content

Scanner excerpt · README.md (reported line 186)May include surrounding context.

EOF

sudo systemctl daemon-reload sudo systemctl enable ralph-loop sudo systemctl start ralph-loop

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

systemctl enable establishes session persistence for a loop designed to repeatedly invoke AI tooling, making the agent continue across reboots without further operator action. In the context of a code-writing loop with optional auto-approval modes, persistence increases the blast radius of mistakes, misuse, or compromised prompts/configuration.

Content

Scanner excerpt · README.md (reported line 186)May include surrounding context.

EOF

sudo systemctl daemon-reload sudo systemctl enable ralph-loop sudo systemctl start ralph-loop

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The README explicitly references auto-approve modes such as --full-auto and --dangerously-skip-permissions, which reduce or remove human approval barriers for an AI coding agent. In the context of a loop that repeatedly drives code changes, this materially increases the chance of unsafe autonomous actions if the surrounding sandboxing and branch isolation guidance is ignored or misapplied.

Content

Scanner excerpt · README.md (reported line 192)May include surrounding context.

md
## Safety

⚠️ Auto-approve flags (`--full-auto`, `--dangerously-skip-permissions`) give the agent write access.

- Run in a dedicated branch
- Use a sandbox for untrusted code

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises script generation, but its documentation instructs users to operate autonomous coding loops that can change code, run tests, commit to git, and call external notification tooling. This creates a scope-deception issue: the apparent low-risk utility masks higher-risk orchestration behavior that can materially affect a codebase and surrounding systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrase 'an AI loop' is overly broad and can cause the skill to activate in contexts far beyond the specialized Ralph-loop use case. Overbroad activation increases the chance that users unintentionally invoke autonomous orchestration guidance in situations where they expected a simpler or safer behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The parallel execution section introduces background process spawning and multi-worktree autonomous agent execution, which is materially broader than simple loop-script generation. This increases operational risk by enabling concurrent code changes and harder-to-audit activity, especially if invoked in trusted environments without clear disclosure.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The skill recommends '--full-auto', which allows autonomous approval of workspace actions. Even if sandboxed, this reduces human oversight in a loop designed to modify code, run tests, and commit changes, making accidental harmful changes more likely.

Content

Scanner excerpt · SKILL.md (reported line 300)May include surrounding context.

md
### Codex
- Requires git repository
- **Each `codex exec` is a fresh session** — no memory between calls
- `--full-auto`: Auto-approve in workspace (sandboxed)
- `--yolo`: No sandbox, no approvals (dangerous but fast)
- Default model: gpt-5.2-codex

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
94% confidence
Finding

The documentation explicitly promotes a no-approval mode ('--yolo') for Codex, removing sandboxing and human approval barriers around autonomous code actions. In the context of a coding loop skill, this materially increases the chance of destructive or unsafe repository and local-environment changes from an agent acting without review.

Content

Scanner excerpt · SKILL.md (reported line 301)May include surrounding context.

md
- Requires git repository
- **Each `codex exec` is a fresh session** — no memory between calls
- `--full-auto`: Auto-approve in workspace (sandboxed)
- `--yolo`: No sandbox, no approvals (dangerous but fast)
- Default model: gpt-5.2-codex

### Claude Code

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The Claude Code guidance includes '--dangerously-skip-permissions', which disables normal permission checks for an autonomous coding workflow. This is dangerous because it encourages bypassing built-in safeguards while the agent can inspect, modify, and potentially damage project files or invoke additional commands.

Content

Scanner excerpt · SKILL.md (reported line 305)May include surrounding context.

md
- Default model: gpt-5.2-codex

### Claude Code
- `--dangerously-skip-permissions`: Auto-approve (use in sandbox)
- No git requirement
- Each invocation is fresh

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 319)May include surrounding context.

md
## Safety

⚠️ **Auto-approve flags are dangerous.** Always:
1. Run in a dedicated directory/branch
2. Use a sandbox (Docker/VM) for untrusted projects
3. Have `git reset --hard` ready as escape hatch

Static analysis

No suspicious patterns detected.