Ralph LoopSAFE
An improved implementation of the Ralph Wiggum technique for autonomous AI agent orchestration
Overview
An improved implementation of the Ralph Wiggum technique for autonomous AI agent orchestration
e28854ad0e63OBSERVED · 2026-10-07Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| gemini-cli | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: ralph-loop description: Run, monitor, resume, merge, and debug Ralph loops. Use this skill whenever the user asks to operate `ralph run` or `ralph loops`, inspect loop state, recover suspended loops, analyze diagnostics, or unblock merge queue issues. --- # Ralph Loop Use this skill to operate Ralph loops from the outside. ## Use This Skill For - Starting or continuing a Ralph run with the right `-c` and `-H` inputs - Inspecting loop state, worktrees, logs, history, and diffs - Resuming a hook-suspended loop - Merging or discarding completed worktree loops - Debugging unexpected loop behavior with current diagnostics files ## Workflow 1. Start with `ralph loops list` or `ralph loops list --json` to establish the current state. 2. If the user wants execution, run `ralph run ...` with the right core config and hats source. 3. If the loop is stuck or suspicious, inspect `logs`, `history`, and `diff` before changing state. 4. If the loop is suspended, read `.ralph/suspend-state.json` and use `ralph loops resume <id>`. 5. If a loop is queued or in `needs-review`, inspect the diff first, then use `merge`, `process`, `retry`, or `discard` as appropriate. 6. Use diagnostics when you need detailed evidence about hats, events, tool calls, parse errors, or performance. ## Guardrails - Prefer the CLI over direct edits to `.ralph` state files. - Treat tasks and memories as the canonical runtime systems; do not center scratchpad as the primary state model. - Inspect diffs before merging. - Only remove lock or queue artifacts when the underlying process is confirmed dead. - Manual edits under `.ralph/` are last-resort recovery steps and should be called out explicitly when used. ## Read These References When Needed - For command recipes and operator flows: `references/commands.md` - For diagnostics files and suspend-state details: `references/diagnostics.md`
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
.claude/skills/ralph-tools/SKILL.md
CLAUDE.md
Gates applied: no_behavioural_pass.
e28854ad0e63full audit observations/trust-audit/skill/mikeyobrien__ralph-loop.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | e28854ad0e63 | SAFE | B | 89 | first audit |
Questions
What does the Ralph Loop skill do?
An improved implementation of the Ralph Wiggum technique for autonomous AI agent orchestration
Is Ralph Loop safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Ralph Loop access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Ralph Loop work with?
Its documentation mentions gemini-cli. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (e28854ad0e63), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.