karpathy
Fail
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The setup instructions in
ml_training.mdinclude a command to fetch a script from a remote URL and execute it directly in the shell (curl -LsSf https://astral.sh/uv/install.sh | sh). - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone a repository from GitHub (
github.com/karpathy/autoresearch.git) and run training scripts from within it, which involves executing code not distributed with the skill itself. - [COMMAND_EXECUTION]: The autonomous loop allows the agent to execute arbitrary shell commands via the
executoragent. This includes running measurement commands provided by the user, executing dynamically generated Python scripts (karpathy_learner.py), and using piped execution to Node.js (node -e) to parse results. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because the
researcheragent ingests untrusted content from the project codebase (viaRead,Grep,Glob). This data can influence the commands generated for and executed by theexecutoragent, which possesses high-privilege capabilities such as file modification and shell access. [Ingestion points]: Project codebase read bykarpathy-researcher.md. [Boundary markers]: None identified in instructions. [Capability inventory]:karpathy-executor.mdhasBash,Write, andEdittools. [Sanitization]: No sanitization of input from project files before interpolation into agent instructions.
Recommendations
- AI detected serious security threats
Audit Metadata