distill

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core skill behavior is benign and well-scoped for local analysis, but it includes an unnecessary remote update check and a transitive skill-update instruction (`npx skills update distill`). That raises supply-chain and trust-chain concerns, though there is no clear credential theft, exfiltration, or malware behavior in the skill itself.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 05:51 AM
Package URL
pkg:socket/skills-sh/abpai%2Fskills%2Fdistill%2F@d5ccc29f0b26862d96e70f30f20a4c6bfc29cab3
Security Audit — socket — distill