karpathy-kb
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's core workflow involves ingesting untrusted data from external URLs via scraping (using the firecrawl skill) and storing it in the
raw/directory. The instructions then direct the agent to read these raw sources and compile them into wiki articles. This creates a risk where malicious instructions embedded in a scraped webpage could influence the agent's behavior during the compilation or query phases. - Ingestion points: Untrusted data enters the system through Procedure 2, which uses
firecrawl scrapeorfirecrawl crawlto populate the<topic>/raw/articles/directory. - Boundary markers: Missing. There are no specific instructions or markers implemented to prevent the agent from following instructions embedded within the raw source files during the synthesis process.
- Capability inventory: The agent has the capability to write to the local filesystem (
wiki/concepts/), modify existing files, and perform searches usinggrepacross the vault. - Sanitization: There is no mentioned sanitization of the scraped markdown content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill relies on several local scripts and shell commands for its operations, which is standard for a technical management tool but should be monitored.
- Local Scripts: The skill executes
bash .claude/skills/karpathy-kb/scripts/new-topic.shto scaffold directories andpython3 .claude/skills/karpathy-kb/scripts/lint-wiki.pyto check for structural issues. - System Utilities: The instructions guide the agent to use standard tools like
grep,sed,ln, andtouchfor managing the knowledge base files.
Audit Metadata