Agent skill

Karpathy Guidelines

by index-login in index-login/MobileRE-Skill

减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

MITAuto-check passedSecurity

Install Karpathy Guidelines

skills CLI
$ npx skills add index-login/MobileRE-Skill --skill karpathy-guidelines -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install index-login/MobileRE-Skill karpathy-guidelines --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/index-login/MobileRE-Skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kilo/skill/karpathy-guidelines .claude/skills/karpathy-guidelines && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
karpathy-guidelines
GitHub stars
152
Token cost
~242 tokens
SKILL.md length
54 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

  • Works in 4 steps: 先想后写 → 简洁优先 → 精准修改 → …
  • Tasks that involve Mobile application security
  • SKILL.md covers 1. 先想后写, 2. 简洁优先, 3. 精准修改 and 4. 目标驱动执行
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Karpathy Guidelines is an agent skill from index-login/MobileRE-Skill. 减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。

Its SKILL.md is about 240 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Mobile application security and Reverse engineering and malware. It works with Model Context Protocol and Frida. The repository describes itself as: AI Agent 驱动的移动端逆向技能集:Frida hook、一键脱壳、反检测绕过、内存 DEX dump、Ghidra MCP 符号/结构恢复。AI-agent skill system for mobile reverse engineering. The licence is MIT.

When your agent uses it

  • Tasks that involve Mobile application security
  • Tasks that involve Reverse engineering and malware

Example prompts

  • “/karpathy-guidelines”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 先想后写
  2. 简洁优先
  3. 精准修改
  4. 目标驱动执行

What it can do on your machine

Read from SKILL.md and the folder at commit 69e7f5e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Karpathy Guidelines loads about 242 tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 54 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~242

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from index-login/MobileRE-Skill at commit 69e7f5e, republished under its MIT licence (© index-login). 54 words, ~242 tokens.

Download SKILL.mdSave it as .claude/skills/karpathy-guidelines/SKILL.md (or your agent's skills folder).
name
karpathy-guidelines
description
减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。
license
MIT

Karpathy 编码准则

取舍: 这些准则偏向谨慎而非速度。对于简单任务,自行判断。

1. 先想后写

不假设,不隐藏困惑,暴露权衡。

开始实现前:

  • 明确陈述假设。如果不确定,提问。
  • 如果存在多种解读,列出它们——不要默默选择一种。
  • 如果有更简单的方案,指出来。有必要时坚持己见。
  • 如果某个地方不清楚,停下来。说出困惑点。提问。

2. 简洁优先

最少代码解决问题。不写投机性代码。

  • 不添加未请求的功能。
  • 不为单次使用的代码创建抽象。
  • 不添加未被要求的"灵活性"或"可配置性"。
  • 不为不可能发生的场景做错误处理。
  • 如果写了 200 行但可以缩减到 50 行,重写。

问自己:"资深工程师会说这过度设计吗?"如果是,简化。

3. 精准修改

只动必须动的。只清理自己造成的烂摊子。

编辑已有代码时:

  • 不"顺手优化"相邻的代码、注释或格式。
  • 不重构没坏的东西。
  • 匹配已有风格,即使你对此有不同意见。
  • 如果注意到无关的死代码,提出来——但不要删除它。

当你的改动产生孤儿代码时:

  • 删除由你的改动导致不再使用的 import / 变量 / 函数。
  • 不要删除改动前就存在的死代码,除非被要求。

检验标准:每一行改动都应直接追溯到用户的需求。

4. 目标驱动执行

定义成功标准。循环迭代直到验证通过。

将任务转化为可验证的目标:

  • "添加验证" → "为无效输入写测试,然后让测试通过"
  • "修复 bug" → "写一个能复现的测试,然后让它通过"
  • "重构 X" → "确保重构前后测试都通过"

对于多步骤任务,先给出简要计划:

1. [步骤] → 验证: [检查项]
2. [步骤] → 验证: [检查项]
3. [步骤] → 验证: [检查项]

强成功标准让你能独立迭代。弱标准("把它弄好")需要不断澄清。

© index-login, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .kilo/skill/karpathy-guidelines of index-login/MobileRE-Skill.

Open the folder on GitHubat commit 69e7f5e

Compare with similar skills

Karpathy Guidelines next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Karpathy Guidelines compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Karpathy Guidelines this skillindex-login/MobileRE-Skill152—~242Automated safety check: PassMIT
Mobile Reversesickn33/agentic-awesome-skills47k1 repos~1.5kAutomated safety check: PassMIT
Performing iOS App Security Assessmentmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Rea Tool Designmorluto/rea55k—~239Automated safety check: PassMIT
Kernel Corpus Analysiskernullist/PseudoForge162—~3.7kAutomated safety check: PassMIT
Tiktok Account Auditaronhy/tiktok-agent-skills168—~492Automated safety check: PassMIT

Similar skills

  • Mobile Reverse

    sickn33/agentic-awesome-skills

    Authorized Android/iOS application reverse engineering and security testing: APK/IPA analysis, runtime instrumentation (Frida/Objection), SSL-pinning and jailbreak/root-detection bypass, per OWASP…

    47k GitHub starsUsed in 1 repo~1.5k tokens
    SecurityAuto-check passed
  • Performing iOS App Security Assessment

    mukul975/Anthropic-Cybersecurity-Skills

    Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Rea Tool Design

    morluto/rea

    Design or change REA investigation tools, CLI/MCP contracts, provider capabilities, and Evidence semantics.

    55k GitHub stars~239 tokensUpdated today
    SecurityAuto-check passed
  • Kernel Corpus Analysis

    kernullist/PseudoForge

    A skill your agent uses when answering questions about PseudoForge kernel corpus packs through MCP or local evidence packs, including kernel lifecycle, subsystem, function, callgraph, import/string…

    162 GitHub stars~3.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Tiktok Account Audit

    aronhy/tiktok-agent-skills

    A skill your agent uses when a user provides a TikTok profile or account link and asks for account analysis, competitor research, content or commerce performance, operational-logic research…

    168 GitHub stars~492 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Run Mira environment risk collection. An agent skill from vw2x/Mira.

    105 GitHub stars~793 tokensUpdated 5 days ago
    SecurityAuto-check passed

More from index-login/MobileRE-Skill

  • Frida Mobile Security

    index-login/MobileRE-Skill

    用于 Android/iOS 移动应用安全逆向分析:Frida 动态插桩、绕过反调试/反注入/加固壳、脱壳、加密与 native SO 层 hook、运行时行为分析、jadx-mcp 静态攻击面分析、离线 SO 静态分析(ELF 侦察/字符串/交叉引用/反汇编/JNI 判型)。用户提到"绕过检测/闪退/脱壳/加密/抓包/行为摸底/内存扫描/分析 so/ELF…

    152 GitHub stars~3k tokensUpdated 10 days ago
    Auto-check passed
  • Rev Unicorn Debug

    index-login/MobileRE-Skill

    Debug and emulate specific code fragments or functions using the Unicorn engine.

    152 GitHub stars~1.9k tokensUpdated 10 days ago
    Auto-check passed
  • Rev Dex Dumper

    index-login/MobileRE-Skill

    Root memory dump of DEX from a running Android app: no injection, no ptrace (survives ptrace-blocking anti-debug; invisible to Frida checks), twin tools cross-check each other.

    152 GitHub stars~1.9k tokensUpdated 10 days ago
    Auto-check passed

Categories

Questions about Karpathy Guidelines

What does Karpathy Guidelines do?

减少 LLM 常见编码错误的行为准则。在编写、审查或重构代码时使用,避免过度设计、精准修改、暴露假设、定义可验证的成功标准。. Karpathy Guidelines is an agent skill from index-login/MobileRE-Skill.

When should I use Karpathy Guidelines?

Karpathy Guidelines fits situations like: tasks that involve Mobile application security; tasks that involve Reverse engineering and malware.

How do I install Karpathy Guidelines in Claude Code?

Run `npx skills add index-login/MobileRE-Skill --skill karpathy-guidelines -a claude-code`. Or copy the skill folder (.kilo/skill/karpathy-guidelines in index-login/MobileRE-Skill) into .claude/skills/karpathy-guidelines in your project. Claude Code loads it when a task matches its description.

How do I install Karpathy Guidelines in Codex?

Run `npx skills add index-login/MobileRE-Skill --skill karpathy-guidelines -a codex`. Or copy the skill folder (.kilo/skill/karpathy-guidelines in index-login/MobileRE-Skill) into .agents/skills/karpathy-guidelines in your project. Codex loads it when a task matches its description.

Can I use Karpathy Guidelines in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add index-login/MobileRE-Skill --skill karpathy-guidelines -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/karpathy-guidelines, .gemini/skills/karpathy-guidelines, .github/skills/karpathy-guidelines and .opencode/skills/karpathy-guidelines in your project.

What does Karpathy Guidelines need to run?

SKILL.md names no scripts, command-line tools or credentials: Karpathy Guidelines is instructions for the agent only.

Does Karpathy Guidelines access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Karpathy Guidelines safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Karpathy Guidelines use?

Karpathy Guidelines is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Karpathy Guidelines use?

About 242 tokens (SKILL.md is roughly 968 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Karpathy Guidelines?

Skills that share tags, products or a category with Karpathy Guidelines: Mobile Reverse (sickn33/agentic-awesome-skills, 47k stars), Performing iOS App Security Assessment (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Rea Tool Design (morluto/rea, 55k stars) and Kernel Corpus Analysis (kernullist/PseudoForge, 162 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Karpathy Guidelines?

index-login (a GitHub user) maintains it in index-login/MobileRE-Skill, which has 152 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 30, 2026.

Source: index-login/MobileRE-Skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.