distill

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core auditing purpose broadly matches the parsing and reporting behavior, and GitHub CLI usage is consistent with analyze mode. However, the skill’s footprint is wider than necessary because it scrapes credentials from a separate local .env, autonomously creates GitHub issues/labels, and can forward report contents to another service. These behaviors make it higher risk than a normal reporting skill, though not confirmed malware.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:57 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fdistill%2F@bf1217a8b0adeb22b897bbab05c67a49b35f3645