skill-distill

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and file access are mostly coherent for skill distillation, and there is no explicit credential harvesting or third-party data routing. However, it requires executing multiple locally installed helper scripts from ~/.claude/skills whose provenance is not publicly verifiable from the provided evidence, creating a meaningful supply-chain and transitive-trust risk disproportionate to a documentation-style skill.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 8, 2026, 03:26 AM
Package URL
pkg:socket/skills-sh/lanyasheng%2Fauto-improvement-orchestrator-skill%2Fskill-distill%2F@c94fbd5b047f92205960678f6ae38a03c7178926