Early in 2026, Andrej Karpathy posted a list of the mistakes LLMs make when they write code: they assume instead of asking, overbuild, and change code nobody asked them to touch. Jiayuan Zhang turned that list into four rules and published them as a skill. It's one of the most starred skill repos on GitHub, and it's short enough to read in two minutes.
What it does
Four rules, each with a one-line summary in the skill:
- Think before coding. State your assumptions. If a request can mean two things, say so instead of picking one. If something is unclear, stop and ask.
- Simplicity first. The least code that solves the problem. No features, abstractions or configuration nobody asked for.
- Surgical changes. Touch only what the task needs. Match the existing style. Clean up after your own change, and leave other dead code alone (mention it instead).
- Goal-driven execution. Turn the task into something you can check, like a test that should pass, then loop until it does.
The third rule has the test we like best:
The test: Every changed line should trace directly to the user's request.
From SKILL.md by Jiayuan Zhang, MIT.
An example
You ask: "Add a check that the email field isn't empty." Without the rules, it's common to get the check plus a new validation helper, a reformatted file and a renamed variable. With them, the agent adds the check, writes a test for an empty email, runs it, and mentions (without fixing) the unused import it noticed on the way.
When to use it, and when not to
Use it on any codebase you care about, especially someone else's or one with a style of its own. It's a good default for newer developers because it makes the agent's changes small enough to read and understand.
For throwaway scripts and quick prototypes, the extra questions may not be worth it.
What we checked
We read every file in the skill's folder at the commit linked above: just
SKILL.md. We also read the repo's README.md, plugin files and Cursor rule.
There are no scripts, no network access and no allowed-tools; the only link
is to Karpathy's post, for you to read. The repo has no LICENSE file, but the
README, the plugin manifest and the skill's own frontmatter all state MIT.
Our full checklist is in the
guide to checking a skill before you install it.
Rule four pairs well with the verification before completion skill, which makes the agent show the check passing before it says it's done.