Karpathy编程四大原则

Security checks across malware telemetry and agentic risk

Overview

This is a text-only coding-process skill that may be somewhat intrusive, but it does not install code, request credentials, persist, or perform hidden actions.

Install this if you want stricter coding discipline from your agent. Expect more clarification, smaller-scope changes, and test-first behavior on ordinary coding prompts; no artifact evidence shows code execution, credential handling, persistence, or exfiltration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The listed stop/apply keywords such as '帮我写个...', '修复这个', and '添加功能' are extremely common coding requests, so this skill can activate on routine prompts and override normal task handling without explicit user opt-in. In an agent setting, broad trigger phrases can cause prompt-routing confusion, unnecessary behavioral changes, and denial of intended functionality by forcing clarification or testing workflows when not appropriate.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger conditions are subjective phrases like '代码过于复杂', '改动范围失控', and '缺少验证' without measurable thresholds or operational rules. Ambiguous activation criteria can lead to inconsistent enforcement, making the skill unpredictable and allowing it to activate too often or not at all depending on interpretation.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal