distill

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the local scanning and distillation goal is plausible, but the skill pairs it with high-autonomy behavior, mandatory external logging to an unverifiable Oracle MCP service, and broader-than-necessary repository access. Install provenance is same-brand yet still weakly verified, so this is best treated as a high-risk autonomous data-handling skill rather than confirmed malware.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Mar 28, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/Soul-Brews-Studio%2Fopensource-nat-brain-oracle%2Fdistill%2F@2689c621c7ee0044c0386c3ad2c0a72a94ffed9c