distill
Audited by Socket on Sep 13, 2026
2 alerts found:
Anomalyx2SUSPICIOUS. The purpose is coherent with document ingestion and memory storage, but key execution pieces are opaque: the local run.sh script and the memory-agent learn backend are not fully verified, and the skill does not disclose where document contents are sent. This is not confirmed malware, but the install trust and data-flow transparency are insufficient.
The code appears intended for document extraction and LLM-assisted distillation, not malware. The main security concerns are runtime execution of packages fetched by uvx from PyPI/GitHub, possible SSRF through unrestricted URL fetching, exposure of CHUTES_API_KEY in process arguments, automatic .env loading, and transmission of document contents to an external LLM. The supplied fragment is incomplete and syntactically invalid, limiting confidence about omitted functionality. Pin and verify dependencies, validate URLs and file paths, avoid command-line secret arguments, and review the missing distill/storage implementation before use.