distill

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core skill behavior is benign and well-scoped for local analysis, but it includes an unnecessary remote update check and a transitive skill-update instruction (`npx skills update distill`). That raises supply-chain and trust-chain concerns, though there is no clear credential theft, exfiltration, or malware behavior in the skill itself.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Mar 22, 2026, 04:02 PM
Package URL
pkg:socket/skills-sh/abpai%2Fskills%2Fdistill%2F@0900eff4d1a1c95f216ad40550d4a20704511a09