LLM Wiki Karpathy

Security checks across malware telemetry and agentic risk

Overview

The skill's files, instructions, and tooling requests are coherent with a local-first Markdown wiki maintenance workflow and do not ask for unrelated credentials or system access.

This skill appears internally consistent: it's an instruction-first guide for maintaining a local Markdown wiki using a runtime that exposes kb_* tools. Before installing/using it, ensure you have a trustworthy MCP/runtime that actually implements the kb_* tool contract (or the npm package referenced), and review any external package (@harrylabs/llm-wiki-karpathy) or publish scripts before running them locally. The scripts included (init_llm_kb_repo.sh and publish.sh) are developer helpers — running publish.sh will call clawhub and node and perform network actions, so only run them if you trust the package and target. Because the skill can be invoked autonomously by the agent (normal default), confirm your agent's permissions and that the runtime limits file-system access to the intended vault path so the agent cannot read or write unrelated files.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal