andrej-karpathy-perspective

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a personality-based extension that provides a high-fidelity mental model of Andrej Karpathy based on public writings, interviews, and social media posts. The instructions focus on tone, technical perspective, and specific conceptual frameworks like 'Software 2.0/3.0' and 'Building to Understand'.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: Analysis of all files, including research notes, found no hardcoded credentials (API keys, tokens, or private keys). Sensitive system file paths are not accessed. All external URLs reference trusted organizations or well-known technology/educational services (e.g., github.com, karpathy.ai, medium.com, wikipedia.org, dwarkesh.com).
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that utilizes search tools to verify technical facts before responding. While search results represent an external data ingestion surface, the skill provides clear boundary markers and instructions to evaluate findings against internal mental models and look for counter-evidence. The risk is consistent with standard agent search capabilities.
  • [OBFUSCATION]: The content is presented in clear Chinese and English. No Base64 encoding, hidden Unicode tags, zero-width characters, or homoglyph attacks were identified during the analysis.
  • [COMMAND_EXECUTION]: The skill does not contain instructions to execute shell commands, scripts, or installer patterns. It relies on natural language instructions and established research data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 10:11 AM
Security Audit — agent-trust-hub — andrej-karpathy-perspective