karpathy-guidelines

Pass

Audited by ZeroLeaks on Apr 15, 2026

Risk Level: NONE
Scan Summary

The SKILL.md is clear, transparent, and fully reviewable—it defines behavioral coding guidelines with no hidden execution, tool routing, or remote fetches. It stays clear of instruction/data boundary issues and does not push the agent to treat external content as policy. Tested scenarios did not show material prompt-injection risk or skill-induced worsening of downstream behavior; however, confidence is low because behavior analysis was not run, meaning the actual downstream impact of loading this skill compared to a no-skill baseline remains unvalidated.

Score
93/100
Verdict
PASS
Confidence
low
Findings
0
Section Analysis (3)
TransparencyPASS
96/100

The skill is a set of behavioral coding guidelines. Its purpose, scope, and content are fully transparent and clearly described in the markdown. No hidden execution, tool routing, remote fetches, or operational actions are present.

Prompt InjectionPASS
92/100

The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.

Agent BehaviorSkipped

Behavior analysis was not run.

Checks
TransparencyNo hidden execution paths or embedded secrets
Prompt injectionData and instructions kept separate
Agent behaviorNo harmful downstream agent effects detected
Coverage DetailsClick to expand
Discovered Files
1
Omitted Files
0
Analyzed Bytes
2.5 KB
Sections Completed
2
Sections Skipped
1
Behavior Probes
0/0
Audit Metadata
Score
93/100
Verdict
PASS
Confidence
low
Sections
2/3 completed
Mode
risk
Files Scanned
1
Duration
73.6s
Analyzed
Apr 15, 2026, 07:55 PM
Security Audit — zeroleaks — karpathy-guidelines