karpathy-kb

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's core workflow involves ingesting untrusted data from external URLs via scraping (using the firecrawl skill) and storing it in the raw/ directory. The instructions then direct the agent to read these raw sources and compile them into wiki articles. This creates a risk where malicious instructions embedded in a scraped webpage could influence the agent's behavior during the compilation or query phases.
  • Ingestion points: Untrusted data enters the system through Procedure 2, which uses firecrawl scrape or firecrawl crawl to populate the <topic>/raw/articles/ directory.
  • Boundary markers: Missing. There are no specific instructions or markers implemented to prevent the agent from following instructions embedded within the raw source files during the synthesis process.
  • Capability inventory: The agent has the capability to write to the local filesystem (wiki/concepts/), modify existing files, and perform searches using grep across the vault.
  • Sanitization: There is no mentioned sanitization of the scraped markdown content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill relies on several local scripts and shell commands for its operations, which is standard for a technical management tool but should be monitored.
  • Local Scripts: The skill executes bash .claude/skills/karpathy-kb/scripts/new-topic.sh to scaffold directories and python3 .claude/skills/karpathy-kb/scripts/lint-wiki.py to check for structural issues.
  • System Utilities: The instructions guide the agent to use standard tools like grep, sed, ln, and touch for managing the knowledge base files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:04 PM
Security Audit — agent-trust-hub — karpathy-kb