Corpus Sweep
nubjs/nub
Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
Apply Karpathy-style minimalism and anti-dependency principles to code and system design.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-minimalism -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-minimalism --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/karpathy-minimalism .claude/skills/karpathy-minimalism && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "karpathy-minimalism" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-minimalism into .claude/skills/karpathy-minimalism/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-minimalism", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-minimalismType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-minimalism -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-minimalism --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/karpathy-minimalism .agents/skills/karpathy-minimalism && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "karpathy-minimalism" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-minimalism into .agents/skills/karpathy-minimalism/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-minimalism", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-minimalism -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-minimalism --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/karpathy-minimalism .cursor/skills/karpathy-minimalism && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "karpathy-minimalism" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-minimalism into .cursor/skills/karpathy-minimalism/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-minimalism", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LearnPrompt/andrej-karpathy-skills.git --path karpathy-minimalism--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-minimalism -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-minimalism --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/karpathy-minimalism .gemini/skills/karpathy-minimalism && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "karpathy-minimalism" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-minimalism into .gemini/skills/karpathy-minimalism/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-minimalism", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-minimalismInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-minimalism -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/karpathy-minimalism .github/skills/karpathy-minimalism && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "karpathy-minimalism" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-minimalism into .github/skills/karpathy-minimalism/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-minimalism", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-minimalism -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-minimalism --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/karpathy-minimalism .opencode/skills/karpathy-minimalism && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "karpathy-minimalism" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-minimalism into .opencode/skills/karpathy-minimalism/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-minimalism", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
karpathy-minimalismApply Karpathy-style minimalism and anti-dependency principles to code and system design.
Karpathy Minimalism is an agent skill from LearnPrompt/andrej-karpathy-skills. Apply Karpathy-style minimalism and anti-dependency principles to code and system design. Use this skill when the user wants to reduce dependencies, avoid supply chain risks, rewrite something in pure Python or minimal code, audit a project for bloat, design agent-native CLI tools, or says "too many dependencies", "minimize deps", "pure python", "yoink this", "vibe code this", "no frameworks", "agent-native design". Based on 28k-like litellm attack post and 25k-like 243-line GPT post.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security and Model routing and gateways. It works with Python. The repository describes itself as: Karpathy-inspired Agent Skills collection. The licence is MIT.
Read from SKILL.md and the folder at commit 9e46dec. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipnpmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
x.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Karpathy Minimalism loads about 1.6k tokens when it runs. Until then it costs about 127 tokens; SKILL.md has 264 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LearnPrompt/andrej-karpathy-skills at commit 9e46dec, republished under its MIT licence (© LearnPrompt). 264 words, ~1,621 tokens.
.claude/skills/karpathy-minimalism/SKILL.md (or your agent's skills folder).Source: https://x.com/karpathy/status/2036487306585268612 | https://x.com/karpathy/status/2021694437152157847 litellm supply chain attack (~28k likes) | 243-line pure Python GPT (~25k likes)
Every dependency is a liability. Every abstraction you don't understand is a risk.
Karpathy's rule: if you can implement the core in 200 lines of pure Python — do it. Don't install a package that installs 47 transitive dependencies just to get 3 functions.
And: design everything so an LLM agent can use it without friction — CLI-first, markdown-structured, zero magic.
Before pip install or npm install anything:
Q1: Can I implement the core function in < 300 lines?
→ YES: Write it. Paste below as reference.
→ NO: Continue to Q2
Q2: Does this package have < 5 transitive dependencies?
→ YES: OK to use, but pin the version
→ NO: Continue to Q3
Q3: Is this a well-known, audited package (requests, numpy, etc.)?
→ YES: Use it, but still pin version
→ NO: STOP. Either find a simpler alternative or implement yourself.Run this before adding anything to a project:
Audit this dependency for supply chain risk:
Package: [PACKAGE_NAME] v[VERSION]
1. List ALL transitive dependencies (not just direct)
2. Check for recent security advisories
3. Identify any dependencies that are maintained by a single person with < 100 GitHub stars
4. Check if the package does any network calls on import
5. Check if install scripts run arbitrary code (setup.py, postinstall hooks)
Risk score: LOW / MEDIUM / HIGH
Recommendation: USE / AVOID / IMPLEMENT_YOURSELFInstead of installing a package, copy the specific function you need:
Given this package: [PACKAGE_URL or PASTE CODE]
Extract ONLY the function(s) I need for: [SPECIFIC_USE_CASE]
Requirements:
- Pure Python (stdlib only, no imports except builtins + [ALLOWED_STDLIB])
- Under [N] lines
- Add a comment: "# yoinked from [source] on [date]"
- Include a docstring explaining what it does
I need: [SPECIFIC_FUNCTION_NAME or DESCRIPTION]Make everything legible to LLM agents:
| ❌ Agent-Hostile | ✅ Agent-Native |
|---|---|
| GUI-only tools | CLI with clear flags |
| JSON config with magic keys | Commented YAML or Markdown config |
| Monolithic functions | Small, named, single-purpose functions |
| Error: "something went wrong" | Error: "Step 3 failed: expected X, got Y. Try: [suggestion]" |
| Relative paths everywhere | Explicit absolute paths |
| Stateful side effects | Pure functions with explicit IO |
When "yoinking" or implementing from scratch:
#!/usr/bin/env python3
"""
[FUNCTION_NAME] — minimal implementation
yoinked/inspired from: [SOURCE]
date: [DATE]
dependencies: none (stdlib only)
Usage:
python3 [filename].py [args]
Or import:
from [filename] import [function]
"""
# ---- core implementation ---- (~100 lines max for core logic)
def [function](input):
"""
[One sentence description]
Args:
input: [type and description]
Returns:
[type and description]
"""
# implementation
pass
# ---- CLI entry point ----
if __name__ == "__main__":
import sys
if len(sys.argv) < 2:
print("Usage: python3 [filename].py [input]")
sys.exit(1)
result = [function](sys.argv[1])
print(result)Karpathy implemented a full GPT training + inference in 243 lines of pure Python to prove a point: understanding the core matters more than using the abstracted version.
Apply this to any tool you regularly use:
Implement a minimal version of [TOOL/CONCEPT] from scratch.
Requirements:
- Pure Python, stdlib only
- Under 300 lines
- Must demonstrate the core algorithm (not just wrap an API)
- Include inline comments explaining WHY each step works
This is for learning, not production.
Start with the simplest possible working version.Before adding any dependency:
- [ ] Checked PyPI/npm for recent security advisories
- [ ] Verified maintainer is active (last commit < 6 months)
- [ ] Reviewed install scripts (setup.py, package.json scripts)
- [ ] Pinned exact version: package==1.2.3 (not ~=1.2)
- [ ] Checked transitive dep count (pip show --files or npm ls --all)
- [ ] Considered: can we implement this in < 200 lines instead?
For existing projects:
- [ ] Run: pip-audit or npm audit
- [ ] Check for packages not in requirements.txt (pip freeze vs requirements diff)
- [ ] Verify no packages make network calls on import属于工作流:想法到上线(第3步)
| 位置 | 上游 | 下游 |
|---|---|---|
| 第3步(瘦身) | karpathy-agentic-engineering(实现后) | karpathy-supply-chain-hygiene(安全审查) |
完整链路:idea-files → agentic-engineering → minimalism → supply-chain-hygiene → vibe-to-agentic
Audit this project/code for dependency minimalism: <PASTE_CODE_OR_DESCRIBE>. For each dependency: 1) Is it needed? What specific feature does it provide? 2) Can it be replaced with < 200 lines of stdlib code? 3) How many transitive deps does it pull in? 4) Risk score (LOW/MED/HIGH). Then produce a minimized version plan: what to keep, what to yoink, what to rewrite. Output a dependency budget: max N packages, each justified.© LearnPrompt, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in karpathy-minimalism of LearnPrompt/andrej-karpathy-skills.
Open the folder on GitHubat commit 9e46dec
Karpathy Minimalism next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Karpathy Minimalism this skillLearnPrompt/andrej-karpathy-skills | 110 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Corpus Sweepnubjs/nub | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Sca TrivyAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~3.7k | Automated safety check: Pass | Custom licence | |
| Vulners API Python SDKvulnersCom/api | 376 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Cyber NeoHainrixz/cyber-neo | 283 | — | ~5.9k | Automated safety check: Warn | MIT | |
| npm Supply Chain Checkmajiayu000/spellbook | 287 | — | ~1.5k | Automated safety check: Pass | MIT |
nubjs/nub
Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
AgentSecOps/SecOpsAgentKit
Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…
vulnersCom/api
A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
majiayu000/spellbook
Scans a repository, its lockfiles and node_modules for known malicious npm package versions and install-time indicators, using a read-only Python scanner.
jeremylongshore/tons-of-skills-marketplace
Build a dependency-tree map of a project (npm or Python) and trace the path from each known-vulnerable transitive package back to one or more direct dependencies.
LearnPrompt/andrej-karpathy-skills
Apply Andrej Karpathy AI methodology and principles from his 2023-2026 insights. Use this skill when the user wants to apply Karpathy-style thinking, needs…
LearnPrompt/andrej-karpathy-skills
Apply Karpathy-style agentic engineering to any coding or building task.
LearnPrompt/andrej-karpathy-skills
Sets up an autonomous research loop where an agent runs experiments on git branches, logs results and proposes the next iteration while you approve each hypothesis change.
LearnPrompt/andrej-karpathy-skills
Apply the education-first mindset — make everything you build teachable, create nano-project explanations, write for beginners.
LearnPrompt/andrej-karpathy-skills
Create and share ideas as abstract Gist-style specs instead of code — letting agents or others implement.
LearnPrompt/andrej-karpathy-skills
Use LLM as a simulator of expert debates and opposing viewpoints instead of getting a single sycophantic answer.
Works with
Categories
Apply Karpathy-style minimalism and anti-dependency principles to code and system design. Karpathy Minimalism is an agent skill from LearnPrompt/andrej-karpathy-skills. Apply Karpathy-style minimalism and anti-dependency principles to code and system design.
Karpathy Minimalism fits situations like: the user wants to reduce dependencies; avoid supply chain risks; rewrite something in pure Python; audit a project for bloat.
Run `npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-minimalism -a claude-code`. Or copy the skill folder (karpathy-minimalism in LearnPrompt/andrej-karpathy-skills) into .claude/skills/karpathy-minimalism in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-minimalism -a codex`. Or copy the skill folder (karpathy-minimalism in LearnPrompt/andrej-karpathy-skills) into .agents/skills/karpathy-minimalism in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-minimalism -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/karpathy-minimalism, .gemini/skills/karpathy-minimalism, .github/skills/karpathy-minimalism and .opencode/skills/karpathy-minimalism in your project.
Going by SKILL.md and its folder, Karpathy Minimalism needs the command-line tools its instructions call (pip and npm). Our summary lists: Python 3; Node.js.
SKILL.md names 1 domain. As links in the text: x.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Karpathy Minimalism is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Karpathy Minimalism: Corpus Sweep (nubjs/nub, 4.4k stars), Sca Trivy (AgentSecOps/SecOpsAgentKit, 220 stars), Vulners API Python SDK (vulnersCom/api, 376 stars) and Cyber Neo (Hainrixz/cyber-neo, 283 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LearnPrompt (a GitHub user) maintains it in LearnPrompt/andrej-karpathy-skills, which has 110 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on July 10, 2026.
Source: LearnPrompt/andrej-karpathy-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.