ralph-attach

ralph-attach is a skill for Claude Code, Codex from jmagly/aiwg. It costs 15 tokens per session (1,245 once invoked), scanned A, original, MIT.

A tool for following the live output of a running Ralph agent loop, which is a repeated automated coding process, as it writes to a log.

In plain words
What is it for?
Attaching to an active loop, selecting a loop by its ID, and watching its output in real time.
Why use it?
It lets you monitor progress and see new log entries without interrupting the running loop. It also handles cases where no loop is running or several loops need to be distinguished.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/jmagly/aiwg/ralph-attach
Any agent
npx skills add jmagly/aiwg --skill ralph-attach
Clone the repo
git clone --depth 1 https://github.com/jmagly/aiwg

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ralph-attach

README.md
[![agentmods](https://agentmods.dev/badge/skills/jmagly/aiwg/ralph-attach.svg)](https://agentmods.dev/skills/jmagly/aiwg/ralph-attach)
Your own site
<a href="https://agentmods.dev/skills/jmagly/aiwg/ralph-attach"><img src="https://agentmods.dev/badge/skills/jmagly/aiwg/ralph-attach.svg" alt="Measured on agentmods" height="20"></a>
Per session 15 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,245 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00015 $0.01245
Opus 5 $0.00008 $0.00622
Sonnet 5 $0.00003 $0.00249
Haiku 4.5 $0.00002 $0.00125

Measured 6d ago against content hash 7420129cb8a0, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-05, from the pricing page.

Security

Grade A, and why

ralph-attach scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agentic/code/addons/agent-loop/skills/ralph-attach/SKILL.md · 157 lines

How it starts

The opening of the file, as written. The whole thing — 157 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Al Attach

Attach to a running external agent loop and tail its output log in real time. Press Ctrl+C to detach without interrupting the loop.

Natural Language Triggers

Users may say:

  • "ralph attach"
  • "attach to ralph"
  • "follow ralph"
  • "watch ralph output"
  • "tail the agent loop"
  • "stream ralph progress"

Parameters

--loop-id (optional)

The ID of the loop to attach to. If omitted, attaches to the most recently started active loop.

/ralph-attach --loop-id abc123

When multiple loops are active, you must specify --loop-id. Run /ralph-status first to list active loop IDs.

Behavior

When triggered:

  1. Read .aiwg/ralph-external/loops/ to find active loop state files
  2. If --loop-id is not provided, select the loop with the most recent startedAt timestamp that has status: "running"
  3. If no active loop is found, report clearly and exit
  4. If multiple loops are active and no --loop-id is given, list them and prompt the user to specify
  5. Resolve the loop's logFile path from its state JSON (typically .aiwg/ralph-external/logs/<loop-id>.log)
  6. Begin reading the log file from the current end, streaming new lines as they are appended
  7. Display each new line to the user as it arrives, prefixed with a timestamp
  8. Continue until the user presses Ctrl+C or the loop reaches a terminal state (succeeded, failed, aborted)
  9. On loop completion, print a final status banner and exit cleanly

Output format while tailing:

[10:42:01] Agent loop abc123 — ACTIVE (iteration 3/10)
[10:42:01] Running verification: npm test
[10:42:03] PASS src/auth/auth.test.ts
[10:42:03] Tests: 12 passed, 0 failed
[10:42:04] Iteration 3: VERIFIED — criteria met
[10:42:04] Agent loop: SUCCESS

On loop completion:

═══════════════════════════════════════════
Agent Loop Completed: SUCCESS
Loop ID: abc123
Iterations: 3
Duration: 4m 12s
Report: .aiwg/ralph-external/reports/abc123.md
═══════════════════════════════════════════

Detached from loop abc123.

Read the full file on GitHub · 157 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 157 lines · 15 tokens per session scan A 7420129cb8a0

Subscribe to this mod's changes

ralph-attach is a skill published in the GitHub repository jmagly/aiwg (209 stars, last pushed yesterday), licensed MIT. It adds 15 tokens to every session and 1,245 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

vertical-real-estate

Residential-proptech domain knowledge so architect / pm aren't naive when speccing real-estate products (listings, lead-crm, transaction-coordination, property-mgmt). Codifies MLS/IDX reality, listing status lifecycle + syndication canonical-source, long-cycle lead nurture, transaction-coordination as the high-pain…

avelikiy/great_cto · 99 tokens

skeptical-triage

Reusable 3-round self-challenge + arbiter pattern for filtering false positives from findings/verdicts. Use when the cost of a false-positive gate block exceeds the cost of 4 extra LLM turns.

avelikiy/great_cto · 49 tokens

vertical-hr-recruiting

Domain-knowledge primer for the HR & recruiting vertical (ATS, onboarding, workforce scheduling, engagement). Applied by architect/pm during spec authoring so they aren't naive about hiring pipelines, the admitted offer→onboard data-carry gap, EEO/I-9 compliance, and shift-coverage rules. Stops the four products from…

avelikiy/great_cto · 90 tokens

lifecycle-messaging

Email/SMS lifecycle and deliverability framework for SMB Product-Builder products that send transactional or lifecycle messages (booking reminders, CRM sequences, receipts, win-back). Codifies provider selection (Resend/Postmark/Twilio/SendGrid), domain auth (SPF/DKIM/DMARC), consent and compliance (TCPA, CAN-SPAM…

avelikiy/great_cto · 132 tokens

pm-planning

Decomposition methodology for pm agent — turns an approved ARCH document into a Beads task list with explicit dependencies, time-boxes, and acceptance criteria. The pipeline can only orchestrate work it can see; this skill defines what "seeable work" looks like.

avelikiy/great_cto · 57 tokens

well-architected

6-pillar architecture review framework. Adapted from AWS Well-Architected for use by greatcto's architect agent on every non-nano ARCH document. Forces explicit answers across operational excellence, security, reliability, performance, cost, and sustainability — not just feature design.

avelikiy/great_cto · 60 tokens