karpathy-review
Pass
Audited by Gen Agent Trust Hub on Jul 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill provides a framework for manual review of user-provided text. It does not include any executable scripts, binary files, or network-enabled tools. The external references are to well-known services (Twitter and GitHub) and are used for attribution purposes.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external input by asking the user to paste code or plans for review. Although it lacks explicit boundary markers to isolate this untrusted content, the skill does not possess any dangerous capabilities—such as file modification, network operations, or shell command execution—that could be leveraged by a malicious input to compromise the host system.
Audit Metadata