andrej-karpathy-skills — security grade SAFE, quality 63/100

Security audit verdict: SAFE · quality 63/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by multica-ai · AI Tool · ★ 212.9k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is andrej-karpathy-skills safe to install? View the security audit →

About andrej-karpathy-skills

Karpathy-Inspired Claude Code Guidelines Check out my new project Multica — an open-source platform for running and managing coding agents with reusable skills. Follow me on X: https://x.com/jiayuanjy A single file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls. English | 简体中文 The Problems From Andrej's post: "The models make wrong assumptions on your behalf and just run along with them without checking. They don't manage their confusion, don't seek clarifications, don't surface inconsistencies, don't present tradeoffs, don't push back when they should." "They really like to overcomplicate code and APIs, bloat abstractions, don't clean up dead code... implement a bloated construction over 1000 lines when 100 would do." "They still sometimes change/remove comments and code they don't sufficiently understand as side effects, even if orthogonal to the task." The Solution Four principles in one file that directly address these issues: Leverage thr

Quick Facts

Stars212,920
Forks21,574
CategoryAI Tool
Quality Score62.6861967716711/100
Open Issues130
Last Updated2026-04-20
Created2026-01-27
Platformsclaude-code
Est. Tokens~3k

More AI Tool Tools

Explore other popular ai tool tools:

View all AI Tool tools →

Frequently Asked Questions

What is andrej-karpathy-skills?

andrej-karpathy-skills is A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.. It is categorized as a AI Tool with 212.9k GitHub stars.

How do I install or use andrej-karpathy-skills?

You can find installation instructions and usage details in the andrej-karpathy-skills GitHub repository at github.com/multica-ai/andrej-karpathy-skills. The project has 212.9k stars and 21574 forks, indicating an active community.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse AI Tool tools