Ralph Loop

Security checks across malware telemetry and agentic risk

Overview

This is an autonomous code-generation loop that generally matches its stated purpose, but the skill omits declared dependencies/credentials, has an unknown source, and runs scripts that autonomously modify repositories — review before installing or granting access.

Before installing, verify the scripts' contents and the referenced upstream repository (the SKILL.md links to a GitHub project but the skill metadata lacks a homepage). Expect the scripts to modify your repository and run tests — run them in a sandbox or disposable clone first. Confirm whether you have/need Codex/Claude CLI tools and their API keys; do not supply credentials unless you trust the code. If you want to avoid autonomous changes, either set disableModelInvocation:true for this skill or only run the scripts manually after reviewing. If unsure, ask the maintainer for a verified source URL and an explanation of required binaries/credentials.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal