Essence Distiller

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a benign, instruction-only content distillation skill; the main consideration is that submitted content is processed by your agent's configured model.

This skill appears safe to install based on the supplied artifacts. Use normal caution with sensitive documents: anything you ask it to distill will be processed by your agent's model, which may be cloud-hosted depending on your setup.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

#
ASI07: Insecure Inter-Agent Communication
Info
What this means

Private or sensitive documents submitted for distillation may be sent to the user's configured model provider if the agent uses a cloud model.

Why it was flagged

The skill is transparent that user-provided content may be handled by the configured model provider. This is purpose-aligned and disclosed, but users should notice it before submitting confidential content.

Skill content
If your agent uses a cloud-hosted LLM (Claude, GPT, etc.), data is processed by that service as part of normal agent operation.
Recommendation

Only provide content you are comfortable processing with your configured agent/model, and check your model provider's privacy and retention settings for confidential material.