skill-distiller

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent, but the footprint is broader than a simple analyzer because it installs third-party skills and processes untrusted instruction content with write/exec capability. The official `skills.sh` installer reduces malware concern, yet transitive skill installation and indirect prompt-injection exposure make this a medium-high security risk.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Apr 10, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/iliaal%2Fcompound-engineering-plugin%2Fskill-distiller%2F@a73f11ff784d84da0752947f13e02380bc99aa14