karpathy-llm-wiki
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill's instructions, requirements, and behavior are consistent with a local wiki manager: it reads/writes a ~/wiki directory (or a user-specified wikiRoot) and does not request extra credentials or install code.
This skill appears coherent and reasonable for maintaining a local markdown wiki, but consider these precautions before installing: (1) Verify or set ~/.agent-wiki.json so wikiRoot points only to a directory you want the agent to read/write (do not reuse system folders or directories containing secrets). (2) Be aware the agent will create and modify files under that wikiRoot (index.md, log.md, pages); keep backups or use version control if you care about history. (3) When ingesting web URLs or external files, review sources for sensitive data before adding them; the agent may fetch and store content. (4) If you do not want the agent to act autonomously, disable autonomous invocation in the platform (or run the skill only interactively). (5) Because this is instruction-only (no install), risk comes from file writes and network fetches the agent performs at runtime — limit its permissions accordingly.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
