karpathy

Fail

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The setup instructions in ml_training.md include a command to fetch a script from a remote URL and execute it directly in the shell (curl -LsSf https://astral.sh/uv/install.sh | sh).
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone a repository from GitHub (github.com/karpathy/autoresearch.git) and run training scripts from within it, which involves executing code not distributed with the skill itself.
  • [COMMAND_EXECUTION]: The autonomous loop allows the agent to execute arbitrary shell commands via the executor agent. This includes running measurement commands provided by the user, executing dynamically generated Python scripts (karpathy_learner.py), and using piped execution to Node.js (node -e) to parse results.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because the researcher agent ingests untrusted content from the project codebase (via Read, Grep, Glob). This data can influence the commands generated for and executed by the executor agent, which possesses high-privilege capabilities such as file modification and shell access. [Ingestion points]: Project codebase read by karpathy-researcher.md. [Boundary markers]: None identified in instructions. [Capability inventory]: karpathy-executor.md has Bash, Write, and Edit tools. [Sanitization]: No sanitization of input from project files before interpolation into agent instructions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 17, 2026, 01:13 PM