distill

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core auditing purpose broadly matches the parsing and reporting behavior, and GitHub CLI usage is consistent with analyze mode. However, the skill’s footprint is wider than necessary because it scrapes credentials from a separate local .env, autonomously creates GitHub issues/labels, and can forward report contents to another service. These behaviors make it higher risk than a normal reporting skill, though not confirmed malware.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:57 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fdistill%2F@bf1217a8b0adeb22b897bbab05c67a49b35f3645
Security Audit — socket — distill