Agent skill

Distill Shield

by agenmod in agenmod/immortal-skill

Distill Shield:为个人移交资料包生成 Canary 与可选加固策略,提高未授权蒸馏成本;仅适用于有权处置的数据。

MITAuto-check passedDevOps & Cloud

Install Distill Shield

skills CLI
$ npx skills add agenmod/immortal-skill --skill distill-shield -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install agenmod/immortal-skill distill-shield --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/agenmod/immortal-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/distill-shield-skill .claude/skills/distill-shield && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
distill-shield
GitHub stars
1.1k
Token cost
~408 tokens
SKILL.md length
94 words
Files
4
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

Distill Shield:为个人移交资料包生成 Canary 与可选加固策略,提高未授权蒸馏成本;仅适用于有权处置的数据。

  • Works in 6 steps: :威胁模型 → :材料盘点 → :策略选择(准则) → …
  • Tasks that involve Deployment
  • SKILL.md covers 复制给 AI, 语言, 何时激活 and 伦理红线, plus 3 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Distill Shield is an agent skill from agenmod/immortal-skill. Distill Shield:为个人移交资料包生成 Canary 与可选加固策略,提高未授权蒸馏成本;仅适用于有权处置的数据。

Its SKILL.md is about 410 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `README.md`, `kit/shield_gen.py` and `recipes/shield-flow.md`).

It sits in DevOps & Cloud, covering Deployment and Messaging and chat bots. The repository describes itself as: ♾️ 开源数字永生框架 — 从聊天记录蒸馏任何人的七维数字分身。支持微信/飞书/iMessage/Telegram等12+平台,7种角色模板,对齐 OpenClaw Soul Spec 标准。一行指令让你的AI学会蒸馏。 The licence is MIT.

When your agent uses it

  • Tasks that involve Deployment
  • Tasks that involve Messaging and chat bots

Example prompts

  • “/distill-shield”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. :威胁模型
  2. :材料盘点
  3. :策略选择(准则)
  4. :生成
  5. :自检清单
  6. :(可选)给接收方的一页说明

What it can do on your machine

Read from SKILL.md and the folder at commit cdab91b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Distill Shield loads about 408 tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 94 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~408

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from agenmod/immortal-skill at commit cdab91b, republished under its MIT licence (© agenmod). 94 words, ~408 tokens.

Download SKILL.mdSave it as .claude/skills/distill-shield/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
distill-shield
description
Distill Shield:为个人移交资料包生成 Canary 与可选加固策略,提高未授权蒸馏成本;仅适用于有权处置的数据。
license
MIT

复制给 AI

  • 本 Skill 唯一入口:当前文件 distill-shield-skill/SKILL.md。
  • 仓库根:假定 immortal-skill/(或含本目录与 kit/ 的克隆根)。
  • 从仓库根运行生成脚本(推荐,避免路径歧义):
bash
python3 distill-shield-skill/kit/shield_gen.py --output ./handover-bundle --label "我的移交包"

Distill Shield

语言

根据用户第一条消息的语言,全程使用同一语言。

何时激活

  • 用户要「防蒸馏」「加固资料包」「移交前埋 Canary」。
  • 用户运行 kit/shield_gen.py 后需要根据输出做伦理与可读性检查。

伦理红线

  • 仅对本人或已获授权的数据使用;禁止对他人资料恶意投毒。
  • 不承诺数学上不可攻破;承诺 可检测性、审计成本、部分管线干扰。

路径约定

  • 本 Skill 根目录 {baseDir} = distill-shield-skill/。

操作顺序

Phase 0:威胁模型
  • 蒸馏场景:一次性 LLM 蒸馏 vs 批量训练 vs 仅人类阅读?
  • 接收方:家人 / 律师 / 公司?(决定策略强度)
Phase 1:材料盘点
  • 格式、是否分块检索、是否经 OCR。
Phase 2:策略选择(准则)
策略对人对自动化管线可被绕过
Canary 唯一字符串低影响(可放附录)泄露时可检索剔除后丢失
提示注入段需标注阅读区可能干扰单次 LLM 蒸馏预处理可剥离
矛盾样本可能困惑读者污染蒸馏一致性人工可识别
Phase 3:生成

在 distill-shield-skill/ 目录内时:

bash
python3 kit/shield_gen.py --output ./handover-bundle --label "我的移交包"

在 仓库根(推荐,与「复制给 AI」一致):

bash
python3 distill-shield-skill/kit/shield_gen.py --output ./handover-bundle --label "我的移交包"

将生成的 CANARY.txt 与说明合并进实际交付目录。

Phase 4:自检清单
  • 第三方隐私已脱敏
  • Canary 已记录在安全处(便于日后比对)
  • 人类读者能看懂「附录为技术性标记」
Phase 5:(可选)给接收方的一页说明

解释「附录含技术性标记,用于完整性校验,非正文内容」。

不做的事

  • 不提供针对具体模型的对抗样本保证。
  • 不帮助绕过合法安全控制。

© agenmod, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in distill-shield-skill of agenmod/immortal-skill.

  • SKILL.md
  • README.md
  • kit/shield_gen.py
  • recipes/shield-flow.md

Open the folder on GitHubat commit cdab91b

Compare with similar skills

Distill Shield next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Distill Shield compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Distill Shield this skillagenmod/immortal-skill1.1k—~408Automated safety check: PassMIT
Hermes Production Gateway Operationshewi333/Mom-n-Pop-Skills122—~2kAutomated safety check: WarnMIT
Doca Container DeploymentNVIDIA/skills3.5k—~2.5kAutomated safety check: PassApache-2.0
Static Deploynexu-io/nexu3.3k—~989Automated safety check: PassMIT
Miniprogram Developmentaiskillstore/marketplace430—~2.5kAutomated safety check: PassNone
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0

Similar skills

  • Hermes Production Gateway Operations

    hewi333/Mom-n-Pop-Skills

    Procedures for changing the model, restarting and quietly tuning a live Hermes gateway that serves end-users on messaging platforms such as Telegram.

    122 GitHub stars~2k tokensUpdated 28 days ago
    DevOps & CloudAuto-check: warnings
  • Official

    A skill your agent uses when the user is hands-on deploying an in-bundle DOCA service container (Argus, DMS, Firefly, or UROM service) on a BlueField — kubelet standalone watching a static-pod…

    3.5k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Static Deploy

    nexu-io/nexu

    Deploy static pages to nexu.space. An agent skill from nexu-io/nexu.

    3.3k GitHub stars~989 tokensUpdated 5 mo ago
    Frontend & DesignAuto-check passed
  • Miniprogram Development

    aiskillstore/marketplace

    WeChat Mini Program development skill for building, debugging, previewing, testing, publishing, and optimizing mini program projects.

    430 GitHub stars~2.5k tokensUpdated today
    Productivity & AutomationAuto-check passed
  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from agenmod/immortal-skill

  • Immortal Skill

    agenmod/immortal-skill

    通用数字永生框架:从聊天记录、社交媒体、文档等多平台数据中蒸馏任何人的数字分身——支持自己、同事、导师、亲人、伴侣/前任、朋友、公众人物 7 种角色模板,接入国内外 12+ 数据平台。

    1.1k GitHub stars~927 tokensUpdated 5 mo ago
    Auto-check passed
  • Distill Protocol

    agenmod/immortal-skill

    蒸馏协议:为个人数字资料生成人类可读条款与机器可读 manifest;戏称「牛马保护法」仅为传播梗,非法律意见. An agent skill from agenmod/immortal-skill.

    1.1k GitHub stars~423 tokensUpdated 5 mo ago
    Auto-check passed
  • Steamer

    agenmod/immortal-skill

    蒸笼:蒸馏任何人的叙事入口——对齐数字永生引擎,强调生活化「蒸」与公开方法论顾问场景;委托上级 kit/personas 执行。

    1.1k GitHub stars~401 tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about Distill Shield

What does Distill Shield do?

Distill Shield:为个人移交资料包生成 Canary 与可选加固策略,提高未授权蒸馏成本;仅适用于有权处置的数据。. Distill Shield is an agent skill from agenmod/immortal-skill.

When should I use Distill Shield?

Distill Shield fits situations like: tasks that involve Deployment; tasks that involve Messaging and chat bots.

How do I install Distill Shield in Claude Code?

Run `npx skills add agenmod/immortal-skill --skill distill-shield -a claude-code`. Or copy the skill folder (distill-shield-skill in agenmod/immortal-skill) into .claude/skills/distill-shield in your project. Claude Code loads it when a task matches its description.

How do I install Distill Shield in Codex?

Run `npx skills add agenmod/immortal-skill --skill distill-shield -a codex`. Or copy the skill folder (distill-shield-skill in agenmod/immortal-skill) into .agents/skills/distill-shield in your project. Codex loads it when a task matches its description.

Can I use Distill Shield in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agenmod/immortal-skill --skill distill-shield -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/distill-shield, .gemini/skills/distill-shield, .github/skills/distill-shield and .opencode/skills/distill-shield in your project.

What does Distill Shield need to run?

Going by SKILL.md and its folder, Distill Shield needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Distill Shield access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Distill Shield safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Distill Shield use?

Distill Shield is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Distill Shield use?

About 408 tokens (SKILL.md is roughly 1.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Distill Shield?

Skills that share tags, products or a category with Distill Shield: Hermes Production Gateway Operations (hewi333/Mom-n-Pop-Skills, 122 stars), Doca Container Deployment (NVIDIA/skills, 3.5k stars), Static Deploy (nexu-io/nexu, 3.3k stars) and Miniprogram Development (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Distill Shield?

agenmod (a GitHub user) maintains it in agenmod/immortal-skill, which has 1,077 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on April 15, 2026.

Source: agenmod/immortal-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.