ralph
Run Specification-First Development Loops
Vague software requests often lead to rework and drift. Ralph helps Claude, Codex, and Claude Code clarify requirements, create specs, and verify progress through bounded loops.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "ralph" from https://skillstore.io/skills/supercent-io-ralph.md and its manifest at https://skillstore.io/api/skills/supercent-io-ralph/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "ralph". Interview me about a task management CLI.
Expected outcome:
Ralph asks focused questions about users, storage, commands, priority rules, and success criteria before suggesting any implementation.
Using "ralph". Fix all failing tests with a five iteration limit.
Expected outcome:
Ralph reports each attempt, lists remaining failures, records verification scores, and stops when tests pass or the limit is reached.
Using "ralph". Check whether this implementation drifted from the seed.
Expected outcome:
Ralph compares the result with the original goals, constraints, and ontology, then highlights areas that need correction.
Security Audit
CriticalMost external-command findings are false positives caused by Markdown backticks, fenced examples, or literal prompt text. The confirmed risks are persistent writes to hidden agent configuration, Codex developer instruction injection, and broad Gemini hook guidance that can change agent behavior beyond one task.
Confirmed security concerns (2)
Capability review items (24)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (155)
๐ Network access (6)
๐ Filesystem access (28)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/supercent-io-ralph/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/supercent-io-ralph?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/supercent-io-ralph?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/supercent-io-ralph/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/supercent-io-ralph.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
supercent-io. (2026). ralph security audit report (audit version 4) [Author version 3.0.0]. Skillstore. https://skillstore.io/skills/supercent-io-ralph/audits/4BibTeX citation
@techreport{supercent-io-supercent-io-ralph-2026,
author = {supercent-io},
title = {ralph security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/supercent-io-ralph/audits/4},
note = {Author version 3.0.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "ralph security audit report (audit version 4)"
version: "3.0.0"
type: report
authors:
- name: "supercent-io"
date-released: "2026-07-07"
url: "https://skillstore.io/skills/supercent-io-ralph/audits/4"
identifiers:
- type: other
value: "skillstore:supercent-io-ralph:audit:4"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Clarify a Product Request
Use a Socratic interview to turn a vague feature idea into explicit goals, constraints, and acceptance criteria.
Fix a Failing Build
Run a bounded Ralph loop that attempts fixes, verifies results, records failures, and stops at success or the iteration cap.
Control Project Drift
Compare implementation progress against the original seed specification and decide when correction is needed.
Try These Prompts
Use Ralph to interview me about this idea before writing code: [describe the product or feature].
Create a Ralph seed specification from our interview. Include goals, constraints, acceptance criteria, and open questions.
Run Ralph on this task with a maximum of five iterations: fix the failing checks and report verification after each iteration.
Evaluate the current implementation against the seed spec, identify drift, and propose the next evolution step with a stop condition.
Best Practices
- Set an explicit maximum iteration count before starting any Ralph loop.
- Review generated setup scripts before allowing changes to agent configuration files.
- Keep the seed specification short, testable, and tied to observable acceptance criteria.
Avoid
- Do not use Ralph to bypass user review for risky file, shell, or network actions.
- Do not start long loops from unclear goals or missing acceptance criteria.
- Do not install global hooks without understanding the commands they run.
Frequently Asked Questions
What does Ralph do?
Does Ralph write code by itself?
Why does it ask questions first?
Can I use it with Codex?
Is the loop unlimited?
What should I review before installing?
Developer Details
Author
supercent-ioLicense
MIT
Author version
v3.0.0
Skillstore revision
r1
Ref
f93e9bb0daca99badb6a7e574b97737155d57cb3
Maintenance freshness
7/18/2026
Usage
22 downloads ยท 146 views
File structure