The skill is a real security-audit tool, but it can send project contents to external AI services and includes broad auto-run examples without enough consent controls.
Review this before installing in sensitive environments. Use the local scanner or a local model for private repositories unless your organization has approved sending code to OpenRouter, OpenAI-compatible providers, or Anthropic. Disable automatic pre-commit/pre-publish triggers unless they are scoped to approved repositories, consider turning off caching for sensitive projects, and run dependency scans in a sandbox for untrusted codebases.