ralph-specum — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited ralph-specum (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Use this as the primary Codex surface for Ralph Specum. It carries the full reusable workflow and can handle the entire command surface directly when helper skills are not installed.
references/workflow.md for the phase flow, branch and worktree behavior, quick mode, and command routingreferences/state-contract.md for .ralph-state.json, .progress.md, commit rules, and resume semanticsreferences/path-resolution.md for specs_dirs, .current-spec, ambiguity handling, and default directory behaviorreferences/parity-matrix.md for Claude-to-Codex feature translation and command mappingscripts/resolve_spec_paths.py for spec roots, current spec, and unique or ambiguous name resolutionscripts/merge_state.py for safe top-level state mergesscripts/count_tasks.py for task counts and next incomplete taskassets/templates/ for the canonical Ralph markdown file shapesassets/bootstrap/ when the user wants optional project-local Codex guidanceHandle these intents directly:
| Intent | Action |
|---|---|
| Start, new, resume, quick mode | Follow the start flow in references/workflow.md |
| Triage | Delegate to triage-analyst sub-agent to decompose into epic and specs |
| Research | Delegate to research-analyst sub-agent to write research.md |
| Requirements | Delegate to product-manager sub-agent to write requirements.md |
| Design | Delegate to architect-reviewer sub-agent to write design.md |
| Tasks | Delegate to task-planner sub-agent to write tasks.md |
| Implement | Delegate each task to spec-executor sub-agent until complete or blocked |
| Status | Show active spec, backlog state, and per-root listing |
| Switch | Update .current-spec only |
| Cancel | Stop execution and clean up state, confirm before destructive delete |
| Index | Generate specs/.index/ component and external specs |
| Refactor | Delegate to refactor-specialist sub-agent to update spec files |
| Feedback | Open or draft GitHub feedback |
| Help | Summarize the surface and next commands |
If the corresponding helper skill is installed and the user invoked it explicitly, keep behavior aligned with that helper. If not, perform the action here.
.claude/ralph-specum.local.md as the settings source when present../specs when no valid config exists..current-spec in the default specs root.source, name, basePath, phase, taskIndex, totalTasks, taskIteration, maxTaskIterations, globalIteration, maxGlobalIterations, commitSpec, and relatedSpecs.awaitingApproval, quickMode, granularity, epicName, discoveredSkills, and native task sync metadata..progress.md after every phase and after every implementation attempt.Commit line in tasks during implementation unless the user explicitly disables task commits.fine when unset, and continue into implementation in the same session.After completing any phase artifact (research, requirements, design, tasks), you MUST:
The ONLY exception is --quick mode. Without --quick, you MUST NOT auto-continue to the next phase. This is non-negotiable.
research.md, requirements.md, design.md, tasks.md, or refactored spec files outside quick mode:approve current artifactrequest changescontinue to <named next step>continue to <named next step> as approval of the current artifact and permission to proceed.start or new, summarize the resolved spec and stop unless the user explicitly asked for quick or autonomous flow. The next choice should point to continue to research.specs/.current-epic and per-epic state in specs/_epics/<epic-name>/.[P] markers for safe parallel work and [VERIFY] checkpoints for explicit quality validation.Bootstrap project-local files only when the user wants them.
Suggested bootstrap files:
assets/bootstrap/AGENTS.md to give a consumer repo local Ralph guidanceassets/bootstrap/ralph-specum.local.md to seed local settingsDo not bootstrap by default. Installation into $CODEX_HOME/skills is enough.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.