This appears to be a real local transcription skill, but it can automatically install unpinned software from a third-party package mirror despite strong offline/privacy claims.
Review before installing. This skill does not show exfiltration or destructive behavior, but first use may download and install unpinned Python packages and Whisper models, including from a third-party mirror. Install dependencies yourself in a virtual environment if possible, verify the package source, and avoid running it on sensitive recordings in shared or synced folders unless you are comfortable with transcript files being saved there.