# Anti-Distill Skill: every install command stops at the literal text repo-url

> anti-distill is a Skill file, not a program. It reads a work-experience document you wrote, rates each passage for replaceability, and returns a submission copy with the operational content thinned out plus a private copy that keeps it. The page documents this twice, in English and Chinese.

**leilei926524-tech/anti-distill** — 反蒸馏 Skill：清洗你被迫写的 Skill 文件，看起来完整，核心知识留给自己。Anti-distillation for employee Skills.

- Repository: https://github.com/leilei926524-tech/anti-distill
- Stars: 2,434 · Forks: 287
- Language: Unknown
- License: not declared
- Published: 2026-09-28 · Updated: 2026-09-28 · Language: en
- Canonical page: https://hysenlabs.com/projects/leilei926524-tech-anti-distill

## All three install commands end at a literal placeholder

The installation section gives three routes and every one of them stops in the same place:

```bash
# Install to current project
mkdir -p .claude/skills
git clone <repo-url> .claude/skills/anti-distill

# Or install globally
git clone <repo-url> ~/.claude/skills/anti-distill
```

```bash
git clone <repo-url> ~/.openclaw/workspace/skills/anti-distill
```

The angle-bracketed text is not a placeholder the page explains anywhere, and no sentence on the page supplies the URL to substitute. So the paths are informative and the commands are not runnable as printed. What the three routes do establish is the target layout: a per-project directory under .claude/skills, a per-user directory under the same skills folder, and an OpenClaw workspace path. Running it afterwards is a single slash command, `/anti-distill`, after which the prompts ask which file to read and how hard to strip it.

## The documented structure lists five paths and the tree holds one more

The project structure is given as a tree:

```text
anti-distill/
├── SKILL.md
├── prompts/
│   ├── classifier.md
│   ├── diluter_work.md
│   ├── diluter_persona.md
│   └── diluter_general.md
├── README.md
├── INSTALL.md
└── examples/
    └── zhangsan_before_after.md
```

The repository root holds all of those and one entry the block leaves out. Alongside SKILL.md, the prompts directory, README.md, INSTALL.md and examples, there is an assets directory at the top level, and nothing on the page says what is in it or what references it. The single listed example file, zhangsan_before_after.md, is named after the placeholder identity used throughout Chinese technical writing, which suggests the worked before and after comparison lives there rather than on the page itself.

## Four prompt files map onto the four steps the page describes

The numbered description says the Skill reads your files, works out the replaceability level of each passage, substitutes correct but useless filler for the core knowledge, and writes two files. The prompts directory holds four markdown files, and their names line up with those steps closely enough to read as an implementation of them. classifier.md is the replaceability pass, the one that decides what counts as core. The three diluter files split the substitution stage by the kind of passage being rewritten: work, persona, and general. Nothing on the page describes what separates those three categories, or what the classifier considers high replaceability. There is no executable code in the tree at all, so these files are the implementation, and the two output files are written by the assistant following them rather than by a program.

## The retention percentages are given without saying what is retained

Three intensity levels are tabulated, each with a percentage and an audience:

| Level | Retention | Best For |
|------|--------|---------|
| Light | ~80% | When the company reviews submissions carefully |
| Medium | ~60% | Most scenarios, recommended |
| Heavy | ~40% | When the company only checks whether you submitted something |

The middle row is marked as the recommended default. What the numbers measure is not stated: retention of the original text, of the core knowledge, or of the document's apparent substance. The direction is also left unexplained, since Heavy is the level aimed at an organisation that only checks whether a file arrived, and it retains the least. Read that way the table is consistent, because a document that carries nothing needs no scrutiny to pass. Nothing on the page gives a worked example at any particular level, so the percentages cannot be checked against the output.

## The examples strip operating rules, not just facts

Four before and after pairs show what the substitution looks like. A rule that Redis keys must carry a TTL or the pull request is rejected becomes a sentence about caching following team conventions. A prohibition on HTTP calls inside transactions becomes transaction boundary design being reasonable. A habit of blaming external factors first and never admitting fault proactively becomes a statement about clarifying the full context before locating a cause. Being told a task was almost done and then going silent becomes being in progress and will sync when there is an update. Three of the four remove a specific instruction and leave a principle in its place. The first and second could still be acted on by a reader with experience, and the third and fourth are about interpersonal conduct rather than engineering, which is the category the persona diluter is presumably named for.

## The online demo runs on a third-party site under two different campaign tags

For readers who do not want to install anything, the page points at a hosted demo rather than shipping one:

> [Try anti-distill online](https://socialistic.ai/en/skill/anti-distill-11e494/?utm_source=github&utm_medium=issue&utm_campaign=xhs_github_skill_creator&utm_content=hyperlink)

The Skill runs on someone else's domain, and the path carries a fixed identifier, anti-distill-11e494, so there is one demo instance rather than a per-user sandbox. The query string names a campaign, and the Chinese half of the page links the same demo with a different one, xhs_github_skill instead of xhs_github_skill_creator, so the two language sections send different attribution for the same destination. Both sections say the link is aimed at readers arriving from Xiaohongshu and other social platforms, which matches the campaign names. Since the processing happens on that site, a document pasted into the demo is handled by a third party rather than by the local Skill file.

## MIT is stated in both halves while the tree holds no licence file

The licence is declared twice. The English section ends with a Licence heading and the words MIT License, and the Chinese section repeats it verbatim. The repository root, however, has no licence file among its entries, and the licence field on the repository itself comes back empty. So the page makes a claim that nothing in the tree substantiates, and a reader who needs the actual terms has nothing to open. The same root listing also shows no tests, no build configuration and no code, which is consistent with a repository whose entire payload is markdown. The most recent push to master is dated 2 July 2026, and the repository has no GitHub releases at all, so there is no tag to check the page against either.

## The Chinese half drops the contact address and the community link

The page is a bilingual document with two parallel sets of headings, and the two are not quite symmetrical. The English side closes with a Contact heading carrying an email address, and its Community section holds a single link anchor pointing at a Discord invite. The Chinese side has the same two headings and neither one has anything under it. The English Community anchor is also empty of any image, and the badge rows above both language sections wrap their star, fork, issue, pull request, commit, Discord and X links in anchors with no image inside, so those rows render as nothing. The anchor ids themselves do line up: the navigation links point at en and zh-cn, and both ids exist further down the page, with a third id named community sitting above the empty Chinese community heading.

## Conclusion

What anti-distill actually ships is four markdown prompt files, so the interesting question is not whether it runs but what the two output files are worth. The submission copy is built to read as competent while carrying less, and the intensity table says outright which audience that is for: a company that only checks whether something was submitted. That makes the private backup the real artifact, and it means anyone using this should keep the original Skill file under their own control rather than relying on the generated backup. Two practical checks first. The install commands are not runnable as written, since all three end at a placeholder, so the clone has to be filled in by hand. And the licence is asserted as MIT in both language sections while the tree has no licence file, which is worth raising with the author before any work document goes through it.

## FAQ

### What does the Anti-Distill Skill do with a Skill file?

It reads the file, rates each passage for replaceability, replaces the core knowledge with correct but useless filler, and outputs two files: a sanitized version for submission and a private backup that keeps the original gotchas and judgment calls.

### How do you install the Anti-Distill Skill?

The page gives a per-project path under .claude/skills, a per-user path under the same skills folder, and an OpenClaw workspace path, but each git clone command ends at the placeholder <repo-url> and must be filled in by hand.

### What are the three sanitization intensity levels in Anti-Distill?

Light, Medium and Heavy, each paired with a retention percentage of about 80, 60 and 40 percent. Medium is marked as recommended, and the page does not say what the percentages measure.

### Where does the Anti-Distill Skill's online demo run?

On a third-party site at a fixed path ending in anti-distill-11e494, not in the repository, so documents pasted into it are processed away from the local Skill files.

### What licence does the Anti-Distill Skill repository use?

The page states MIT License in both its English and Chinese sections, while the licence recorded on the repository itself is empty and no licence file appears among the root entries.

## Sources

- [Issues](https://github.com/leilei926524-tech/anti-distill/issues)
- [leilei926524-tech/anti-distill on GitHub](https://github.com/leilei926524-tech/anti-distill)
- [README](https://github.com/leilei926524-tech/anti-distill/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/leilei926524-tech-anti-distill
