Ralph Loop
Security checks across malware telemetry and agentic risk
Overview
This is an autonomous code-generation loop that generally matches its stated purpose, but the skill omits declared dependencies/credentials, has an unknown source, and runs scripts that autonomously modify repositories — review before installing or granting access.
Before installing, verify the scripts' contents and the referenced upstream repository (the SKILL.md links to a GitHub project but the skill metadata lacks a homepage). Expect the scripts to modify your repository and run tests — run them in a sandbox or disposable clone first. Confirm whether you have/need Codex/Claude CLI tools and their API keys; do not supply credentials unless you trust the code. If you want to avoid autonomous changes, either set disableModelInvocation:true for this skill or only run the scripts manually after reviewing. If unsure, ask the maintainer for a verified source URL and an explanation of required binaries/credentials.
SkillSpector
SkillSpector findings are pending for this release.
VirusTotal
No VirusTotal findings
