skills/findbene/skills/karpathy-coder/Gen Agent Trust Hub

karpathy-coder

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes Python's subprocess module to interface with the local Git environment. Specifically, scripts/diff_surgeon.py executes git diff to retrieve changes for noise analysis. This execution is performed using a list of arguments without invoking a shell, which is a secure practice that prevents shell injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by analyzing external and potentially untrusted data such as source code, git diffs, and project plans.
  • Ingestion points: Data enters the context through agents/karpathy-reviewer.md (which reads git diffs) and scripts/assumption_linter.py (which processes text proposals).
  • Boundary markers: No specific delimiters or safety instructions are used to wrap the ingested content.
  • Capability inventory: The skill has the capability to read any file the user provides and execute local Git commands via subprocesses.
  • Sanitization: The input is processed as raw text without sanitization.
  • While the Python analysis tools are regex-based and not susceptible to instruction overrides, the AI sub-agent (karpathy-reviewer) that reviews the diffs and tool outputs could potentially be influenced by instructions hidden within the code comments or documentation it is tasked with reviewing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 01:47 PM
Security Audit — agent-trust-hub — karpathy-coder