skill-distiller

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose mostly matches the behavior, but the skill’s core mechanism installs third-party skills via `npx skills add` from ecosystem-provided source URLs, creating transitive trust and prompt-injection risk beyond simple analysis. Because the installer path is official and same-ecosystem, this is not confirmed malware, but it is a medium-high security risk due to unpinned third-party skill installation, local skill staging, and extra external data sources.

Confidence: 88%Severity: 74%
Audit Metadata
Analyzed At
Jul 16, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/iliaal%2Fwhetstone%2Fskill-distiller%2F@c59420207b75c0a45f08a3c9f03484c9e09317031fc83956cea5b36cbbccc819
Security Audit — socket — skill-distiller