anti-distill: The Skill That Lets Workers Hide Their Best Knowledge in Plain Sight
A prompt-as-code countermeasure for corporate AI training, built to return a polished submission copy and a private backup of the real expertise.
公司要求你把工作经验写成 AI Skill,本质上是在蒸馏你——把你变成可替代的零件。 **反蒸馏 Skill** 是你的反制工具:把你写好的 Skill 文件扔进来,输出一份看起来完整专业、实际上核心知识已被抽掉的"清洗版"。同时生成一份私人备份,记录所有被抽掉的核心知识——这才是你真正的职业资产。
- anti-distill treats company skill writing as a hostile interface and answers it with a split output: one file for submission, one for the worker.
- Its real innovation is not deletion, but selective camouflage that preserves structure while stripping tacit professional value.
- `SKILL.md` makes the repo feel like a tiny application, with classification, dilution, preview, execution, and verification wired together.
- The project is a tactic for self-defense, not a fix for the broader extraction model that created the need for it.
The uncomfortable premise is simple: some companies want employees to turn lived expertise into training fuel. `anti-distill` is a reply to that pressure, and it does not pretend to be neutral. It helps you satisfy the format while keeping the durable parts of your knowledge out of reach.
The Most Interesting Trick Is the Split
This repo is built around a moral sleight of hand. The submitted version stays polished enough to pass review, while the private backup preserves the real value, including thresholds, shortcuts, and the context behind decisions. The slogan is basically: lossier for them, lossless for you.
| Mode | What survives | What it optimizes for |
|---|---|---|
| Light | Most structure and terminology | Passing a careful human review |
| Medium | Surface patterns and some detail | Default workplace use |
| Heavy | Only the shell of the document | Maximum dilution before submission |
`SKILL.md` Is the Orchestrator
The repo reads like prompt-as-code because it is arranged like software. `SKILL.md` is the entry point, and the `prompts/` folder holds the specialized logic for classification and dilution. That modularity matters: it turns a social tactic into a repeatable workflow.
anti-distill/
├── SKILL.md
├── prompts/
│ ├── classifier.md
│ ├── diluter_work.md
│ └── diluter_persona.md
└── examples/
The six-step flow is the tell. Input, intensity selection, classification, preview, execution, verification. That is not a prompt dump. It is a state machine with a human approval loop baked in.
The Classifier Decides What Counts as Core
The classifier is the repo’s sharpest idea because it names what workers actually lose first. Not just PII, but gotchas, judgment intuition, interpersonal networks, and hidden context. That is the tacit layer that makes someone hard to replace.
| Approach | What it removes | Who benefits |
|---|---|---|
| anti-distill | Tacit know-how and work-specific judgment | The worker |
| ordinary anonymization | Names and identifiers | The dataset owner |
| corporate skill extraction | Almost nothing useful | The employer |
How Correct but Useless Gets Manufactured
The dilution layer is deliberately unglamorous. Numerical fuzzing turns precise thresholds into vague guidance. Knowledge downgrading converts a working rule into a safe platitude. Persona bleaching replaces the traits that make someone effective with the traits that make them look compliant.
That combination is why the output can still pass inspection. It keeps the shape, the cadence, and enough vocabulary to look professional, while draining out the leverage. The document still reads like work, but it stops being a useful map of how the work is done.
Why the Project Resonates Beyond One Repo
`anti-distill` lands because it names a real asymmetry. Employers can ask for documentation in the name of AI readiness, but the worker pays the cost if that documentation becomes training material. The repo turns that imbalance into something an individual can push back against.
| Model | Goal | Power dynamic |
|---|---|---|
| anti-distill | Preserve worker value | User-side defense |
| ordinary privacy tooling | Reduce exposure of personal data | Compliance and minimization |
| corporate extraction | Turn experience into model fuel | Employer advantage |
That is why this is bigger than privacy. It is about labor power. The project does not solve the system, but it gives a worker a way to refuse full surrender inside it.
What the Project Gets Right, and What It Cannot Solve
The repo is smart about structure and blunt about purpose. It understands that people rarely need perfect secrecy. They need documents that can survive a review while keeping the real expertise off the record. What it cannot do is change the underlying incentive to extract in the first place.