distil

Warn

Audited by Socket on Mar 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Overall, the Distil skill appears designed for legitimate prototyping and design exploration with a heavy orchestration backbone. However, it introduces notable security concerns around transitive skill installation, reliance on external skill catalogs, and potential unverified code execution during pre-flight and design generation. The footprint is proportionate to a design-prototyping tool, but security posture could be improved by tightening trust boundaries (pinning/verifying external skills, restricting transitive installs, adding input validation/sanitization, and explicit integrity checks for generated artifacts). Given the combination of transitive installations and multi-stage file writes, the risk is better categorized as SUSPICIOUS with elevated review requirements rather than clearly benign until mitigations are in place.

Confidence: 72%Severity: 58%
Audit Metadata
Analyzed At
Mar 10, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/slamb2k%2Fmad-skills%2Fdistil%2F@60fffdd3462c8e5be82004c24591cffabb1e6057