DistillSAFE
A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw
Overview
A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw
80a0afd96301OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
---
name: distill
description: >
Synthesize wiki pages from related memories. One endpoint, one flow:
daemon clusters and synthesizes what it can; agent finishes whatever
the daemon couldn't (no LLM or cluster too big). Invoked as
`/distill [target]`.
argument-hint: "[target | rebuild <page-id> | deep]"
allowed-tools: ["mcp__plugin_origin_origin__recall", "mcp__plugin_origin_origin__distill", "mcp__plugin_origin_origin__create_page", "mcp__plugin_origin_origin__update_page", "mcp__plugin_origin_origin__delete_page", "mcp__plugin_origin_origin__get_page_sources", "Bash"]
---
# /distill
Force a distillation pass now. The daemon's background distill cycles run
on its own clock; `/distill` is the explicit user-triggered pass.
## Mental model
Distillation is four operations bundled into one flow:
- **emerge** — cluster new memories into new pages
- **absorb** — assign orphan memories to existing pages, propose new pages
from topics that 2+ existing pages link to but no page is named for
- **refresh** — regenerate stale pages from their source memories (only when
the user has not edited the page; pages you have touched stay locked)
- **merge** — combine duplicate pages flagged by the daemon's global review
The default flow runs all four. The `rebuild` verb is a destructive opt-in
that overrides the lock on a single page.
## Single flow
One POST to the daemon. Response splits into:
- `pages_created` / `created_ids`: pages the daemon synthesized itself
(only when daemon has an LLM).
- `pending`: clusters the daemon couldn't finish. The agent
synthesizes each in this session and POSTs them back to `/api/pages`.
Trigger timing is the only thing that differs between background distill
cycles and this skill. Code path is the same; daemon hands back
clusters when it can't synthesize; whoever called fills in the rest.
## Flow
### 1. Pick the scope
For bare `/distill`, infer a target from cwd:
```
Bash: top=$(git -C "$PWD" rev-parse --show-toplevel 2>/dev/null); \
common=$(git -C "$PWD" rev-parse --git-common-dir 2>/dev/null); \
if [ -n "$common" ]; then \
case "$common" in /*) root=$(dirname "$common");; *) root=$(cd "$top" && cd "$(dirname "$common")" && pwd);; esac; \
basename "$root"; \
fi
```
- Output → use it (e.g. `origin`).
- Not a git repo → fall back to `basename "$PWD"`.
- Reserved keyword `deep` → no scope (global pass).
- Reserved keyword sequence `rebuild <page-id>` → call
`distill(target=<page-id>, force=true)`. Confirms "Rebuild page <id>?
Your edits will be wiped, page regenerates from sources." before
proceeding. Skip the rest of this skill — single-page rebuild does
not produce `pending` clusters; the daemon's response shape is
`{"status": "ok", "force": true, "page_id": ..., "updated": true}`.
Report verbatim.
For `/distill <arg>` → forward `<arg>` to `target`.
### 2. Call the MCP tool
```
distill(target="<scope>")
```
The tool returns the daemon's full JSON payload as text. Parse it as
JSON. Possible shapes:
```
{
"pages_created": 0,
"scoped": true,
"created_ids": [],
"pending": [
{ "source_ids": [...], "contents": [...], "entity_id": ...,
"entity_name": ..., "space": ..., "estimated_tokens": ... },
...
],
"stale_pages": [
{ "page_id": ..., "title": ..., "summary": ...,
"source_memory_ids": [...], "stale_reason": "source_updated",
"user_edited": false, "sources_updated_count": 3 },
...
],
"stale_truncated": false,
"orphan_topics": [
{ "label": "Topic Z", "count": 3 },
...
]
}
```
The route never invokes the daemon LLM. `created_ids` is always empty
when called from this skill; `pending` carries every cluster the
daemon found. The agent synthesizes them in this session — that's why
the LLM choice is consistent with how the user invoked the skill.
`unresolved` + `hint`: relay to user verbatim and stop.
### 3. Synthesize each `pending` cluster
The daemon route filters out clusters fully covered by an existing
page (subset or Jaccard ≥ 0.8). What remains is either:
- A **brand-new cluster** (no existing page) → create a new page.
- A **refresh candidate** (`existing_page_id` is set) → the cluster
has new memories beyond what's in the matched page. The agent has
LLM access, so the right move is to refresh the existing page in
the same pass.
Cluster shape:
```
pending: [
{
source_ids, contents, entity_id, entity_name, space,
estimated_tokens,
existing_page_id?, existing_page_title?, new_memory_count?
},
...
]
```
For each cluster, first run a **coherence check** before synthesizing:
- Skim every memory in `cluster.contents`.
- If the cluster has ≥ ~4 memories and the topics scatter (entity
shared but the memories cover unrelated sub-topics — e.g. all tagged
`Origin` but spanning RwLock bugs, schema choices, onboarding UI,
migrations, and CSS), the cluster is **incoherent**. Skip
synthesizing it. Record it for the report under "Skipped (low
coherence)" with the existing page title (if refresh) or a short
topic hint (if new).
- Coherent cluster (memories share an actual topic, not just an entity
tag) → proceed to synthesis.
The coherence judgement is something only the agent can do — it needs
to read the prose. Daemon clustering is heuristic; agent is the
final filter against producing a grab-bag page.
For each coherent cluster:
- Title: short noun phrase. Use `existing_page_title` when refreshing
unless the new memories materially change the topic. For new
clusters: `cluster.entity_name` if specific, otherwise derive from
the first memory's content.
- Summary: one sentence — the durable claim.
- Body: 3-7 paragraphs of wiki prose. Use `[[wikilinks]]`. Cite source
ids inline with `(source: mem_XXX)`.
**New cluster** (no `existing_page_id`) — call the MCP tool:
```
create_page(title="...", summary="...", content="...",
entity_id="<cluster.entity_id or omit>",
space="Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
80a0afd96301full audit observations/trust-audit/skill/davepoon__distill.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 80a0afd96301 | SAFE | B | 89 | first audit |
Questions
What does the Distill skill do?
A single hub to find Claude Skills, Agents, Commands, Hooks, Plugins, and Marketplace collections to extend Claude Code, Claude Desktop, Agent SDK and OpenClaw
Is Distill safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Distill access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (80a0afd96301), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.