Bom Audit
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-supply-chain-hygiene --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/karpathy-supply-chain-hygiene .claude/skills/karpathy-supply-chain-hygiene && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "karpathy-supply-chain-hygiene" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-supply-chain-hygiene into .claude/skills/karpathy-supply-chain-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-supply-chain-hygiene", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-supply-chain-hygieneType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-supply-chain-hygiene --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/karpathy-supply-chain-hygiene .agents/skills/karpathy-supply-chain-hygiene && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "karpathy-supply-chain-hygiene" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-supply-chain-hygiene into .agents/skills/karpathy-supply-chain-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-supply-chain-hygiene", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-supply-chain-hygiene --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/karpathy-supply-chain-hygiene .cursor/skills/karpathy-supply-chain-hygiene && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "karpathy-supply-chain-hygiene" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-supply-chain-hygiene into .cursor/skills/karpathy-supply-chain-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-supply-chain-hygiene", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LearnPrompt/andrej-karpathy-skills.git --path karpathy-supply-chain-hygiene--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-supply-chain-hygiene --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/karpathy-supply-chain-hygiene .gemini/skills/karpathy-supply-chain-hygiene && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "karpathy-supply-chain-hygiene" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-supply-chain-hygiene into .gemini/skills/karpathy-supply-chain-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-supply-chain-hygiene", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-supply-chain-hygieneInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/karpathy-supply-chain-hygiene .github/skills/karpathy-supply-chain-hygiene && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "karpathy-supply-chain-hygiene" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-supply-chain-hygiene into .github/skills/karpathy-supply-chain-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-supply-chain-hygiene", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-supply-chain-hygiene --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/karpathy-supply-chain-hygiene .opencode/skills/karpathy-supply-chain-hygiene && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "karpathy-supply-chain-hygiene" agent skill from https://github.com/LearnPrompt/andrej-karpathy-skills/tree/main/karpathy-supply-chain-hygiene into .opencode/skills/karpathy-supply-chain-hygiene/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "karpathy-supply-chain-hygiene", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
karpathy-supply-chain-hygieneApply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface.
Karpathy Supply Chain Hygiene is an agent skill from LearnPrompt/andrej-karpathy-skills. Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface. Use this skill when the user wants to audit project dependencies, is concerned about supply chain attacks, wants to set up secure dependency management, needs to review a requirements.txt or package.json, or says "dependency audit", "supply chain risk", "check packages", "secure dependencies", "pin versions", "check pypi". Based on Karpathy 28k-like litellm supply chain post.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Supply chain security. It works with npm. The repository describes itself as: Karpathy-inspired Agent Skills collection. The licence is MIT.
Read from SKILL.md and the folder at commit 9e46dec. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pipnpmFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
x.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Karpathy Supply Chain Hygiene loads about 1.8k tokens when it runs. Until then it costs about 134 tokens; SKILL.md has 189 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from LearnPrompt/andrej-karpathy-skills at commit 9e46dec, republished under its MIT licence (© LearnPrompt). 189 words, ~1,750 tokens.
.claude/skills/karpathy-supply-chain-hygiene/SKILL.md (or your agent's skills folder).Source: https://x.com/karpathy/status/2036487306585268612 "Software horror: litellm PyPI supply chain attack" — ~28k likes
Every dependency is a door you didn't build, maintained by someone you don't know.
The litellm incident Karpathy flagged: a widely-used LLM library got compromised via its transitive dependencies. If your project pulled litellm, you were exposed — and you probably didn't even know litellm was in your stack until it was too late.
Karpathy's response: minimize deps, prefer simple implementations, audit everything.
Run this for any project before deployment or after any dependency update:
Perform a full supply chain security audit for this project.
Dependency file contents:
[PASTE requirements.txt / package.json / Gemfile / go.mod]
For each direct dependency, analyze:
1. Maintainer health: single maintainer? Last commit? GitHub stars?
2. Transitive depth: how many packages does it pull in?
3. Install-time code execution: does it run arbitrary code on install?
4. Network calls on import: does importing trigger outbound connections?
5. Version pinning: are we using exact versions or ranges?
Risk assessment per package:
- HIGH RISK: (list criteria)
- MEDIUM RISK: (list criteria)
- LOW RISK: (list criteria)
Priority actions: [what to fix first]Before adding any new package:
Security pre-check for: [PACKAGE NAME] v[VERSION]
1. PyPI/npm stats: weekly downloads? Known? Established?
2. GitHub: https://github.com/[owner/repo] — stars, last commit, open issues?
3. Transitive deps: run `pip show [package]` or `npm ls [package]` — how deep does it go?
4. setup.py / postinstall: does it run code on install?
5. Import-time behavior: what does `import [package]` actually do?
Risk verdict: SAFE / VERIFY_FURTHER / AVOID
Alternative: if risky, what can I use instead or implement myself?Transform a loose requirements file to a pinned, audited one:
Harden this requirements.txt / package.json for production security.
Current file:
[PASTE FILE]
Output a new version that:
1. Pins all packages to exact versions (== not ~=)
2. Adds a comment for each package: what it's used for, why we need it
3. Flags any packages that could be eliminated with minimal effort
4. Groups by category: core / dev / testing
5. Adds a header comment with: last audited date, total dep count, audit command to run
Also: what command should I run to check for known vulnerabilities?For each feature you're about to add via a package:
I'm about to add [PACKAGE] to solve [PROBLEM].
Before I do: help me evaluate if I should implement this myself instead.
The function I need: [SPECIFIC FUNCTION/CAPABILITY]
Can this be implemented with:
- Python stdlib only (in < 50 lines)? YES/NO
- One simple function I can paste inline? YES/NO
If yes to either: write the minimal implementation I need.
If no: confirm the package is the right choice and suggest the safest way to import it.For any project that pulls external dependencies:
# Dockerfile template — minimal, audited, isolated
FROM python:3.11-slim # pin exact base image
# Create non-root user
RUN useradd -m -u 1000 appuser
WORKDIR /app
# Copy ONLY requirements first (layer caching)
COPY requirements.txt .
# Install with hash verification
RUN pip install --no-cache-dir --require-hashes -r requirements.txt
# Copy application code
COPY --chown=appuser:appuser . .
USER appuser
CMD ["python", "app.py"]# requirements.txt with hashes (generate with pip-compile --generate-hashes)
requests==2.31.0 \
--hash=sha256:58cd2187423839823... \
--hash=sha256:942c5a758f98d79...If you discover a supply chain compromise:
IMMEDIATE (within 1 hour):
- [ ] Identify: which version of which package is compromised?
- [ ] Check: is this version in our requirements.txt / lock file?
- [ ] Check: is this version installed in any running service?
- [ ] Isolate: take affected services offline if credentials could be exposed
SHORT-TERM (within 24 hours):
- [ ] Rotate: any credentials, tokens, API keys that ran in the affected environment
- [ ] Audit: what data could have been accessed/exfiltrated?
- [ ] Update: pin to a safe version or remove the package
- [ ] Scan: check all other packages for similar issues
LONG-TERM:
- [ ] Add automated scanning (pip-audit, npm audit, Dependabot)
- [ ] Implement hash pinning for critical projects
- [ ] Consider: can we eliminate this dependency entirely?# Python
pip-audit # check for known vulns
pip freeze | pip-audit --stdin # audit installed packages
safety check # alternative scanner
# Node.js
npm audit
npm audit fix # auto-fix where safe
# Check transitive deps
pip show [package] # see direct deps
pip-tree [package] # see full tree
# Generate hashed requirements
pip-compile --generate-hashes requirements.in属于工作流:想法到上线(第4步)
| 位置 | 上游 | 下游 |
|---|---|---|
| 第4步(安全检查) | karpathy-minimalism(瘦身后) | karpathy-vibe-to-agentic(最终收尾) |
完整链路:idea-files → agentic-engineering → minimalism → supply-chain-hygiene → vibe-to-agentic
Audit this dependency before I install it: <PACKAGE_NAME> v<VERSION>. Produce: 1) Transitive dependency count and tree, 2) Maintainer activity (last commit, bus factor), 3) Known CVEs or security advisories, 4) Any postinstall hooks or network calls on import, 5) Safer minimal alternative (or "implement yourself in N lines"), 6) Pinned install command if approved. Risk score: LOW/MEDIUM/HIGH. Recommendation: USE/AVOID/IMPLEMENT_YOURSELF.© LearnPrompt, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in karpathy-supply-chain-hygiene of LearnPrompt/andrej-karpathy-skills.
Open the folder on GitHubat commit 9e46dec
Karpathy Supply Chain Hygiene next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Karpathy Supply Chain Hygiene this skillLearnPrompt/andrej-karpathy-skills | 110 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Bom Auditcdxgen/cdxgen | 1.1k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Vex Authoringrelizaio/rearm | 127 | — | ~2.9k | Automated safety check: Pass | AGPL-3.0 | |
| Dependency Update Auditbacknotprop/plannotator | 9.3k | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| Supply Chain Risk Auditortrailofbits/skills | 7.5k | — | ~1.7k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Corpus Sweepnubjs/nub | 4.4k | — | ~2.4k | Automated safety check: Pass | MIT |
cdxgen/cdxgen
Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…
relizaio/rearm
Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.
backnotprop/plannotator
Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.
trailofbits/skills
Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…
nubjs/nub
Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).
briiirussell/cybersecurity-skills
Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.
LearnPrompt/andrej-karpathy-skills
Apply Andrej Karpathy AI methodology and principles from his 2023-2026 insights. Use this skill when the user wants to apply Karpathy-style thinking, needs…
LearnPrompt/andrej-karpathy-skills
Apply Karpathy-style agentic engineering to any coding or building task.
LearnPrompt/andrej-karpathy-skills
Sets up an autonomous research loop where an agent runs experiments on git branches, logs results and proposes the next iteration while you approve each hypothesis change.
LearnPrompt/andrej-karpathy-skills
Apply the education-first mindset — make everything you build teachable, create nano-project explanations, write for beginners.
LearnPrompt/andrej-karpathy-skills
Create and share ideas as abstract Gist-style specs instead of code — letting agents or others implement.
LearnPrompt/andrej-karpathy-skills
Use LLM as a simulator of expert debates and opposing viewpoints instead of getting a single sycophantic answer.
Works with
Categories
Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface. Karpathy Supply Chain Hygiene is an agent skill from LearnPrompt/andrej-karpathy-skills. Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface.
Karpathy Supply Chain Hygiene fits situations like: the user wants to audit project dependencies; is concerned about supply chain attacks; wants to set up secure dependency management; needs to review a requirements.txt.
Run `npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a claude-code`. Or copy the skill folder (karpathy-supply-chain-hygiene in LearnPrompt/andrej-karpathy-skills) into .claude/skills/karpathy-supply-chain-hygiene in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a codex`. Or copy the skill folder (karpathy-supply-chain-hygiene in LearnPrompt/andrej-karpathy-skills) into .agents/skills/karpathy-supply-chain-hygiene in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/karpathy-supply-chain-hygiene, .gemini/skills/karpathy-supply-chain-hygiene, .github/skills/karpathy-supply-chain-hygiene and .opencode/skills/karpathy-supply-chain-hygiene in your project.
Going by SKILL.md and its folder, Karpathy Supply Chain Hygiene needs the command-line tools its instructions call (pip and npm). Our summary lists: Python 3; Node.js.
SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: x.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Karpathy Supply Chain Hygiene is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Karpathy Supply Chain Hygiene: Bom Audit (cdxgen/cdxgen, 1.1k stars), Vex Authoring (relizaio/rearm, 127 stars), Dependency Update Audit (backnotprop/plannotator, 9.3k stars) and Supply Chain Risk Auditor (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LearnPrompt (a GitHub user) maintains it in LearnPrompt/andrej-karpathy-skills, which has 110 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on July 10, 2026.
Source: LearnPrompt/andrej-karpathy-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.