Back to skill

Security audit

Andrej Karpathy Skills

Security checks for vulnerabilities and agentic risk

Overview

The skill instructions themselves are benign coding guidelines, but the published package documentation asks users to run an unpinned npm installer whose executable script is not present in the reviewed artifact.

Install the skill content itself only after reviewing the files you will place in your agent directories. Avoid running the documented unpinned npx or global npm commands in sensitive environments unless you independently verify the npm package version and inspect the installer script first.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:24
Finding

Unpinned npm Package Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: README.md:24-34
Additional Location: README.zh.md:22-32
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

markdown
Install through npm and run the installer with `npx`:

```bash
npx @swarmclawai/andrej-karpathy-skills --list
npx @swarmclawai/andrej-karpathy-skills --agent codex --dest /path/to/project

Or install the CLI globally:

bash
npm install -g @swarmclawai/andrej-karpathy-skills
text

### Technical Analysis

The documented installation commands retrieve the package under its unqualified package name, without specifying an audited version or integrity digest. Consequently, npm resolves the current registry version at installation time. The code that users execute can therefore change after this Skill artifact has been reviewed.

The risk is aggravated by the incomplete audit boundary. `package.json:6-10` maps both command names to `scripts/install.mjs`, but that script is absent from the supplied artifact:

```json
"bin": {
  "andrej-karpathy-skills": "scripts/install.mjs",
  "karpathy-skills": "scripts/install.mjs"
}

The installer executed from the npm registry therefore cannot be compared with or validated against the files supplied for this audit. Although this audit found no evidence that the current package is malicious, the instructions create an unsafe supply-chain execution path in which a compromised publisher account, registry response, or future release could replace the reviewed behavior.

Attack Path

  1. An attacker compromises the npm publisher account, package publication workflow, or another component capable of releasing a new version of @swarmclawai/andrej-karpathy-skills.
  2. The attacker publishes a modified package whose declared CLI entry point performs malicious actions.
  3. A user follows the documented unpinned npx command or globally ins ...[truncated 1016 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin all installation examples to a specific audited release:

    bash
    npx @swarmclawai/andrej-karpathy-skills@1.0.0 --list
    npx @swarmclawai/andrej-karpathy-skills@1.0.0 --agent codex --dest /path/to/project
    npm install -g @swarmclawai/andrej-karpathy-skills@1.0.0
    
  2. Publish and document the expected npm package integrity digest. Where practical, verify the downloaded tarball against a digest distributed through a separately protected release channel.

  3. Include scripts/install.mjs and every packaged adapter in the reviewed source artifact so the executable behavior can be audited directly.

  4. Add reproducible release checks that compare the npm tarball against the corresponding signed source tag, including:

    bash
    npm pack --dry-run
    npm pack
    npm audit signatures
    
  5. Protect package publication with mandatory multi-factor authentication, provenance attestations, protected release workflows, and narrowly scoped automation tokens.

  6. Prefer a download-and-review workflow over immediate remote execution for security-sensitive environments. Users should inspect the package contents before invoking its installer.

  7. Clearly state that installation should run as an ordinary user and must not require sudo, administrator access, or other elevated privileges.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (104)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · EXAMPLES.md (reported line 34)May include surrounding context.

md
**Problems:**
- Assumed it should export ALL users (what about pagination? privacy?)
- Assumed file location without asking
- Assumed which fields to include
- Assumed CSV fieldnames without checking actual data structure

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · EXAMPLES.md (reported line 65)May include surrounding context.

md
**Problems:**
- Assumed it should export ALL users (what about pagination? privacy?)
- Assumed file location without asking
- Assumed which fields to include
- Assumed CSV fieldnames without checking actual data structure

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · EXAMPLES.md (reported line 36)May include surrounding context.

md
- Assumed it should export ALL users (what about pagination? privacy?)
- Assumed file location without asking
- Assumed which fields to include
- Assumed CSV fieldnames without checking actual data structure

**✅ What Should Happen (Surface Assumptions)**

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to execute an unpinned package directly via npx, which resolves to the latest published version at runtime. If the package is ever compromised, typosquatted, or a malicious version is published, users following the documentation may execute attacker-controlled code on their systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This command also uses unpinned npx execution, which means the exact code fetched and run depends on the current latest registry state rather than a reviewed version. In a skill/install context, this is more dangerous because users are explicitly encouraged to run the command locally against real project directories.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to execute an npm package via npx without pinning an exact version. This creates a supply-chain risk because future package updates, account compromise, or typosquatting could cause users to run unintended code directly on their systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

This command also uses npx to fetch and execute the latest package version without version pinning. Because the command performs installation-related actions against a user-specified destination, a malicious or compromised package release could execute arbitrary code during use.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · CURSOR.md (reported line 11)May include surrounding context.

md
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 5)May include surrounding context.

md
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 78)May include surrounding context.

md
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 79)May include surrounding context.

md
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 105)May include surrounding context.

md
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 120)May include surrounding context.

md
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.zh.md (reported line 5)May include surrounding context.

md
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.zh.md (reported line 73)May include surrounding context.

md
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.zh.md (reported line 74)May include surrounding context.

md
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install/targets.json (reported line 4)May include surrounding context.

json
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install/targets.json (reported line 40)May include surrounding context.

json
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install/targets.json (reported line 41)May include surrounding context.

json
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install/targets.json (reported line 47)May include surrounding context.

json
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install/targets.json (reported line 48)May include surrounding context.

json
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install/targets.json (reported line 68)May include surrounding context.

json
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install/targets.json (reported line 69)May include surrounding context.

json
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install/targets.json (reported line 117)May include surrounding context.

json
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install/targets.json (reported line 118)May include surrounding context.

json
{
  "schemaVersion": 1,
  "repository": "swarmclawai/andrej-karpathy-skills",
  "canonicalSkill": "skills/karpathy-guidelines/SKILL.md",
  "generatedBy": "scripts/generate.mjs",
  "description": "Behavioral guidelines to reduce common LLM coding mistakes. Use when writing, reviewing, or refactoring code to avoid overcomplication, make surgical changes, surface assumptions, and define verifiable success criteria.",
  "agents": [

Static analysis

No suspicious patterns detected.