karpathy-coder
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes Python's
subprocessmodule to interface with the local Git environment. Specifically,scripts/diff_surgeon.pyexecutesgit diffto retrieve changes for noise analysis. This execution is performed using a list of arguments without invoking a shell, which is a secure practice that prevents shell injection. - [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing external and potentially untrusted data such as source code, git diffs, and project plans.
- Ingestion points: Data enters the context through
agents/karpathy-reviewer.md(which reads git diffs) andscripts/assumption_linter.py(which processes text proposals). - Boundary markers: No specific delimiters or safety instructions are used to wrap the ingested content.
- Capability inventory: The skill has the capability to read any file the user provides and execute local Git commands via subprocesses.
- Sanitization: The input is processed as raw text without sanitization.
- While the Python analysis tools are regex-based and not susceptible to instruction overrides, the AI sub-agent (
karpathy-reviewer) that reviews the diffs and tool outputs could potentially be influenced by instructions hidden within the code comments or documentation it is tasked with reviewing.
Audit Metadata