anti-distill: The Skill That Lets Workers Hide Their Best Knowledge in Plain Sight

A prompt-as-code countermeasure for corporate AI training, built to return a polished submission copy and a private backup of the real expertise.

8 min read · leilei926524-tech/anti-distill

A worker feeds a thick skill document into a shredder while a polished copy slides into a company inbox tray. A locked drawer sits beneath the desk as a private backup. The scene explains the repo’s core move: one input becomes two outputs, one for compliance and one for self-preservation.
The repo’s central trick is a split. The outward-facing file stays plausible, while the private copy keeps the useful knowledge intact.

公司要求你把工作经验写成 AI Skill,本质上是在蒸馏你——把你变成可替代的零件。 **反蒸馏 Skill** 是你的反制工具:把你写好的 Skill 文件扔进来,输出一份看起来完整专业、实际上核心知识已被抽掉的"清洗版"。同时生成一份私人备份,记录所有被抽掉的核心知识——这才是你真正的职业资产。

leilei926524-tech, Project Creator · leilei926524-tech/anti-distill: README.md
Key Takeaways

The uncomfortable premise is simple: some companies want employees to turn lived expertise into training fuel. `anti-distill` is a reply to that pressure, and it does not pretend to be neutral. It helps you satisfy the format while keeping the durable parts of your knowledge out of reach.

The Most Interesting Trick Is the Split

This repo is built around a moral sleight of hand. The submitted version stays polished enough to pass review, while the private backup preserves the real value, including thresholds, shortcuts, and the context behind decisions. The slogan is basically: lossier for them, lossless for you.

The machine is not just a prompt. It is a pipeline that classifies, dilutes, splits, and then checks whether the result still looks credible.

ModeWhat survivesWhat it optimizes for
LightMost structure and terminologyPassing a careful human review
MediumSurface patterns and some detailDefault workplace use
HeavyOnly the shell of the documentMaximum dilution before submission

`SKILL.md` Is the Orchestrator

The repo reads like prompt-as-code because it is arranged like software. `SKILL.md` is the entry point, and the `prompts/` folder holds the specialized logic for classification and dilution. That modularity matters: it turns a social tactic into a repeatable workflow.

anti-distill/
├── SKILL.md
├── prompts/
│   ├── classifier.md
│   ├── diluter_work.md
│   └── diluter_persona.md
└── examples/

The six-step flow is the tell. Input, intensity selection, classification, preview, execution, verification. That is not a prompt dump. It is a state machine with a human approval loop baked in.

The Classifier Decides What Counts as Core

A hedcut-style portrait of the repository creator based on a verified GitHub avatar. The portrait gives the article a human anchor for a project that is otherwise mostly about prompt machinery and workplace defense.

The classifier is the repo’s sharpest idea because it names what workers actually lose first. Not just PII, but gotchas, judgment intuition, interpersonal networks, and hidden context. That is the tacit layer that makes someone hard to replace.

A close-up of a page under a magnifying glass, with four bands of content being selectively painted over by bland filler. A notebook beneath the page catches the removed lines. The image explains how the classifier separates surface prose from high-value tacit knowledge.
The classifier is less about filtering text than about identifying where professional value lives.
ApproachWhat it removesWho benefits
anti-distillTacit know-how and work-specific judgmentThe worker
ordinary anonymizationNames and identifiersThe dataset owner
corporate skill extractionAlmost nothing usefulThe employer

How Correct but Useless Gets Manufactured

The dilution layer is deliberately unglamorous. Numerical fuzzing turns precise thresholds into vague guidance. Knowledge downgrading converts a working rule into a safe platitude. Persona bleaching replaces the traits that make someone effective with the traits that make them look compliant.

That combination is why the output can still pass inspection. It keeps the shape, the cadence, and enough vocabulary to look professional, while draining out the leverage. The document still reads like work, but it stops being a useful map of how the work is done.

Why the Project Resonates Beyond One Repo

`anti-distill` lands because it names a real asymmetry. Employers can ask for documentation in the name of AI readiness, but the worker pays the cost if that documentation becomes training material. The repo turns that imbalance into something an individual can push back against.

ModelGoalPower dynamic
anti-distillPreserve worker valueUser-side defense
ordinary privacy toolingReduce exposure of personal dataCompliance and minimization
corporate extractionTurn experience into model fuelEmployer advantage

That is why this is bigger than privacy. It is about labor power. The project does not solve the system, but it gives a worker a way to refuse full surrender inside it.

What the Project Gets Right, and What It Cannot Solve

The repo is smart about structure and blunt about purpose. It understands that people rarely need perfect secrecy. They need documents that can survive a review while keeping the real expertise off the record. What it cannot do is change the underlying incentive to extract in the first place.