rlm-distill

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core summarization purpose is coherent, but the skill’s footprint expands in bulk mode to transitive agent-swarm delegation and likely external model submission of full file contents without documented endpoint, auth, or secret-redaction controls. It is not clearly malicious, but it is broader and riskier than a simple local ledger summarizer.

Confidence: 82%Severity: 64%
Audit Metadata
Analyzed At
Mar 19, 2026, 11:29 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Frlm-distill%2F@53ba9dccd6e52056ee9e8b13b631dc6146e85536