skill-distiller
Warn
Audited by Socket on Jul 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose mostly matches the behavior, but the skill’s core mechanism installs third-party skills via `npx skills add` from ecosystem-provided source URLs, creating transitive trust and prompt-injection risk beyond simple analysis. Because the installer path is official and same-ecosystem, this is not confirmed malware, but it is a medium-high security risk due to unpinned third-party skill installation, local skill staging, and extra external data sources.
Confidence: 88%Severity: 74%
Audit Metadata