Agent skill

Karpathy Supply Chain Hygiene

by LearnPrompt in LearnPrompt/andrej-karpathy-skills

Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface.

MITAuto-check passedSecurity

Install Karpathy Supply Chain Hygiene

skills CLI
$ npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LearnPrompt/andrej-karpathy-skills karpathy-supply-chain-hygiene --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LearnPrompt/andrej-karpathy-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/karpathy-supply-chain-hygiene .claude/skills/karpathy-supply-chain-hygiene && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
karpathy-supply-chain-hygiene
GitHub stars
110
Token cost
~1.8k tokens
SKILL.md length
189 words
Files
1
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface.

  • The user wants to audit project dependencies
  • SKILL.md covers Core Principle, The Full Dependency Audit, The 5-Minute Pre-Install Check and Requirements File Hardening, plus 7 more sections
  • Calls pip and npm; reaches github.com
  • Is concerned about supply chain attacks

What it does

Karpathy Supply Chain Hygiene is an agent skill from LearnPrompt/andrej-karpathy-skills. Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface. Use this skill when the user wants to audit project dependencies, is concerned about supply chain attacks, wants to set up secure dependency management, needs to review a requirements.txt or package.json, or says "dependency audit", "supply chain risk", "check packages", "secure dependencies", "pin versions", "check pypi". Based on Karpathy 28k-like litellm supply chain post.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Supply chain security. It works with npm. The repository describes itself as: Karpathy-inspired Agent Skills collection. The licence is MIT.

When your agent uses it

  • The user wants to audit project dependencies
  • Is concerned about supply chain attacks
  • Wants to set up secure dependency management
  • Needs to review a requirements.txt

Example prompts

  • “dependency audit”
  • “supply chain risk”
  • “check packages”
  • “/karpathy-supply-chain-hygiene”

Requirements

  • Python 3
  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 9e46dec. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pip
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • x.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Karpathy Supply Chain Hygiene loads about 1.8k tokens when it runs. Until then it costs about 134 tokens; SKILL.md has 189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~134
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from LearnPrompt/andrej-karpathy-skills at commit 9e46dec, republished under its MIT licence (© LearnPrompt). 189 words, ~1,750 tokens.

Download SKILL.mdSave it as .claude/skills/karpathy-supply-chain-hygiene/SKILL.md (or your agent's skills folder).
name
karpathy-supply-chain-hygiene
description
Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface. Use this skill when the user wants to audit project dependencies, is concerned about supply chain attacks, wants to set up secure dependency management, needs to review a requirements.txt or package.json, or says "dependency audit", "supply chain risk", "check packages", "secure dependencies", "pin versions", "check pypi". Based on Karpathy 28k-like litellm supply chain post.
disable-model-invocation
false
user-invocable
true
related_skills
karpathy-minimalism, karpathy-agentic-engineering, karpathy-vibe-to-agentic, karpathy-understanding-first

Skill 11: Supply Chain & Security Hygiene(供应链安全卫生)

Source: https://x.com/karpathy/status/2036487306585268612 "Software horror: litellm PyPI supply chain attack" — ~28k likes

Core Principle

Every dependency is a door you didn't build, maintained by someone you don't know.

The litellm incident Karpathy flagged: a widely-used LLM library got compromised via its transitive dependencies. If your project pulled litellm, you were exposed — and you probably didn't even know litellm was in your stack until it was too late.

Karpathy's response: minimize deps, prefer simple implementations, audit everything.

The Full Dependency Audit

Run this for any project before deployment or after any dependency update:

Perform a full supply chain security audit for this project.

Dependency file contents:
[PASTE requirements.txt / package.json / Gemfile / go.mod]

For each direct dependency, analyze:
1. Maintainer health: single maintainer? Last commit? GitHub stars?
2. Transitive depth: how many packages does it pull in?
3. Install-time code execution: does it run arbitrary code on install?
4. Network calls on import: does importing trigger outbound connections?
5. Version pinning: are we using exact versions or ranges?

Risk assessment per package:
- HIGH RISK: (list criteria)
- MEDIUM RISK: (list criteria)  
- LOW RISK: (list criteria)

Priority actions: [what to fix first]

The 5-Minute Pre-Install Check

Before adding any new package:

Security pre-check for: [PACKAGE NAME] v[VERSION]

1. PyPI/npm stats: weekly downloads? Known? Established?
2. GitHub: https://github.com/[owner/repo] — stars, last commit, open issues?
3. Transitive deps: run `pip show [package]` or `npm ls [package]` — how deep does it go?
4. setup.py / postinstall: does it run code on install?
5. Import-time behavior: what does `import [package]` actually do?

Risk verdict: SAFE / VERIFY_FURTHER / AVOID
Alternative: if risky, what can I use instead or implement myself?

Requirements File Hardening

Transform a loose requirements file to a pinned, audited one:

Harden this requirements.txt / package.json for production security.

Current file:
[PASTE FILE]

Output a new version that:
1. Pins all packages to exact versions (== not ~=)
2. Adds a comment for each package: what it's used for, why we need it
3. Flags any packages that could be eliminated with minimal effort
4. Groups by category: core / dev / testing
5. Adds a header comment with: last audited date, total dep count, audit command to run

Also: what command should I run to check for known vulnerabilities?

The Minimal Dependency Philosophy

For each feature you're about to add via a package:

I'm about to add [PACKAGE] to solve [PROBLEM].

Before I do: help me evaluate if I should implement this myself instead.

The function I need: [SPECIFIC FUNCTION/CAPABILITY]

Can this be implemented with:
- Python stdlib only (in < 50 lines)?  YES/NO
- One simple function I can paste inline?  YES/NO

If yes to either: write the minimal implementation I need.
If no: confirm the package is the right choice and suggest the safest way to import it.

Containerization + Isolation Template

For any project that pulls external dependencies:

dockerfile
# Dockerfile template — minimal, audited, isolated
FROM python:3.11-slim  # pin exact base image

# Create non-root user
RUN useradd -m -u 1000 appuser

WORKDIR /app

# Copy ONLY requirements first (layer caching)
COPY requirements.txt .

# Install with hash verification
RUN pip install --no-cache-dir --require-hashes -r requirements.txt

# Copy application code
COPY --chown=appuser:appuser . .

USER appuser

CMD ["python", "app.py"]
# requirements.txt with hashes (generate with pip-compile --generate-hashes)
requests==2.31.0 \
    --hash=sha256:58cd2187423839823... \
    --hash=sha256:942c5a758f98d79...

Incident Response Checklist

If you discover a supply chain compromise:

markdown
IMMEDIATE (within 1 hour):
- [ ] Identify: which version of which package is compromised?
- [ ] Check: is this version in our requirements.txt / lock file?
- [ ] Check: is this version installed in any running service?
- [ ] Isolate: take affected services offline if credentials could be exposed

SHORT-TERM (within 24 hours):
- [ ] Rotate: any credentials, tokens, API keys that ran in the affected environment
- [ ] Audit: what data could have been accessed/exfiltrated?
- [ ] Update: pin to a safe version or remove the package
- [ ] Scan: check all other packages for similar issues

LONG-TERM:
- [ ] Add automated scanning (pip-audit, npm audit, Dependabot)
- [ ] Implement hash pinning for critical projects
- [ ] Consider: can we eliminate this dependency entirely?

Scanning Commands Reference

bash
# Python
pip-audit                           # check for known vulns
pip freeze | pip-audit --stdin      # audit installed packages
safety check                        # alternative scanner

# Node.js  
npm audit
npm audit fix                       # auto-fix where safe

# Check transitive deps
pip show [package]                  # see direct deps
pip-tree [package]                  # see full tree

# Generate hashed requirements
pip-compile --generate-hashes requirements.in

Workflow

属于工作流:想法到上线(第4步)

位置上游下游
第4步(安全检查)karpathy-minimalism(瘦身后)karpathy-vibe-to-agentic(最终收尾)

完整链路:idea-files → agentic-engineering → minimalism → supply-chain-hygiene → vibe-to-agentic

Prompt Contract

text
Audit this dependency before I install it: <PACKAGE_NAME> v<VERSION>. Produce: 1) Transitive dependency count and tree, 2) Maintainer activity (last commit, bus factor), 3) Known CVEs or security advisories, 4) Any postinstall hooks or network calls on import, 5) Safer minimal alternative (or "implement yourself in N lines"), 6) Pinned install command if approved. Risk score: LOW/MEDIUM/HIGH. Recommendation: USE/AVOID/IMPLEMENT_YOURSELF.

Verification Checklist

  • 所有依赖都有 pinned version(==,不是 >=)
  • 已检查 transitive dependency 数量
  • 无 postinstall hook 或已审查其内容
  • 单一维护者的包已标记风险
  • 对高风险依赖提供了自实现替代方案
  • lockfile(requirements.txt / package-lock.json)已提交到 repo

© LearnPrompt, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in karpathy-supply-chain-hygiene of LearnPrompt/andrej-karpathy-skills.

Open the folder on GitHubat commit 9e46dec

Compare with similar skills

Karpathy Supply Chain Hygiene next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Karpathy Supply Chain Hygiene compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Karpathy Supply Chain Hygiene this skillLearnPrompt/andrej-karpathy-skills110—~1.8kAutomated safety check: PassMIT
Bom Auditcdxgen/cdxgen1.1k—~2.4kAutomated safety check: PassApache-2.0
Vex Authoringrelizaio/rearm127—~2.9kAutomated safety check: PassAGPL-3.0
Dependency Update Auditbacknotprop/plannotator9.3k—~1.8kAutomated safety check: PassApache-2.0
Supply Chain Risk Auditortrailofbits/skills7.5k—~1.7kAutomated safety check: NotesCC-BY-SA-4.0
Corpus Sweepnubjs/nub4.4k—~2.4kAutomated safety check: PassMIT

Similar skills

  • Bom Audit

    cdxgen/cdxgen

    Runs supply-chain risk analysis on CycloneDX BOMs with cdx-audit predictive auditing and cdxgen --bom-audit embedded rules, covering npm and PyPI package compromise posture, CI permission risk…

    1.1k GitHub stars~2.4k tokensUpdated today
    SecurityAuto-check passed
  • Vex Authoring

    relizaio/rearm

    Author CycloneDX-VEX or OpenVEX documents that import cleanly into ReARM.

    127 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Dependency Update Audit

    backnotprop/plannotator

    Audits outdated npm and Bun packages for supply chain integrity before bumping them, deferring risky ones and logging every decision.

    9.3k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check passed
  • Supply Chain Risk Auditor

    trailofbits/skills

    Official

    Audits a project's dependencies for supply-chain risk: version-matched advisories for direct dependencies and the full lockfile tree, abandoned or archived upstreams, npm publisher concentration…

    7.5k GitHub stars~1.7k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Corpus Sweep

    nubjs/nub

    Run a large sharded measurement sweep over npm packages (the build-jail catalog probe, or any harness that installs thousands of package-versions and records a verdict per run).

    4.4k GitHub stars~2.4k tokensUpdated yesterday
    SecurityAuto-check passed
  • Dependency Audit

    briiirussell/cybersecurity-skills

    Audit project dependencies, frameworks, languages, and dev tools for known vulnerabilities, CVEs, and security anti-patterns.

    413 GitHub stars~3.2k tokensUpdated 4 mo ago
    SecurityAuto-check: warnings

More from LearnPrompt/andrej-karpathy-skills

All 15 skills in this repo
  • Karpathy Methodology Index

    LearnPrompt/andrej-karpathy-skills

    Apply Andrej Karpathy AI methodology and principles from his 2023-2026 insights. Use this skill when the user wants to apply Karpathy-style thinking, needs…

    110 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Karpathy Agentic Engineering

    LearnPrompt/andrej-karpathy-skills

    Apply Karpathy-style agentic engineering to any coding or building task.

    110 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed
  • AutoResearch Loop

    LearnPrompt/andrej-karpathy-skills

    Sets up an autonomous research loop where an agent runs experiments on git branches, logs results and proposes the next iteration while you approve each hypothesis change.

    110 GitHub stars~1.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Karpathy Education First

    LearnPrompt/andrej-karpathy-skills

    Apply the education-first mindset — make everything you build teachable, create nano-project explanations, write for beginners.

    110 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Karpathy Idea Files

    LearnPrompt/andrej-karpathy-skills

    Create and share ideas as abstract Gist-style specs instead of code — letting agents or others implement.

    110 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Karpathy LLM Simulator

    LearnPrompt/andrej-karpathy-skills

    Use LLM as a simulator of expert debates and opposing viewpoints instead of getting a single sycophantic answer.

    110 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Categories

Questions about Karpathy Supply Chain Hygiene

What does Karpathy Supply Chain Hygiene do?

Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface. Karpathy Supply Chain Hygiene is an agent skill from LearnPrompt/andrej-karpathy-skills. Apply rigorous supply chain security hygiene to software projects — audit dependencies, detect risks, minimize attack surface.

When should I use Karpathy Supply Chain Hygiene?

Karpathy Supply Chain Hygiene fits situations like: the user wants to audit project dependencies; is concerned about supply chain attacks; wants to set up secure dependency management; needs to review a requirements.txt.

How do I install Karpathy Supply Chain Hygiene in Claude Code?

Run `npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a claude-code`. Or copy the skill folder (karpathy-supply-chain-hygiene in LearnPrompt/andrej-karpathy-skills) into .claude/skills/karpathy-supply-chain-hygiene in your project. Claude Code loads it when a task matches its description.

How do I install Karpathy Supply Chain Hygiene in Codex?

Run `npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a codex`. Or copy the skill folder (karpathy-supply-chain-hygiene in LearnPrompt/andrej-karpathy-skills) into .agents/skills/karpathy-supply-chain-hygiene in your project. Codex loads it when a task matches its description.

Can I use Karpathy Supply Chain Hygiene in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LearnPrompt/andrej-karpathy-skills --skill karpathy-supply-chain-hygiene -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/karpathy-supply-chain-hygiene, .gemini/skills/karpathy-supply-chain-hygiene, .github/skills/karpathy-supply-chain-hygiene and .opencode/skills/karpathy-supply-chain-hygiene in your project.

What does Karpathy Supply Chain Hygiene need to run?

Going by SKILL.md and its folder, Karpathy Supply Chain Hygiene needs the command-line tools its instructions call (pip and npm). Our summary lists: Python 3; Node.js.

Does Karpathy Supply Chain Hygiene access the network?

SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: x.com. This is read from the text; nothing was executed.

Is Karpathy Supply Chain Hygiene safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Karpathy Supply Chain Hygiene use?

Karpathy Supply Chain Hygiene is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Karpathy Supply Chain Hygiene use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Karpathy Supply Chain Hygiene?

Skills that share tags, products or a category with Karpathy Supply Chain Hygiene: Bom Audit (cdxgen/cdxgen, 1.1k stars), Vex Authoring (relizaio/rearm, 127 stars), Dependency Update Audit (backnotprop/plannotator, 9.3k stars) and Supply Chain Risk Auditor (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Karpathy Supply Chain Hygiene?

LearnPrompt (a GitHub user) maintains it in LearnPrompt/andrej-karpathy-skills, which has 110 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on July 10, 2026.

Source: LearnPrompt/andrej-karpathy-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.