This local credential-auditing skill is purpose-aligned, but it needs Review because it reads sensitive files outside the workspace and includes remediation commands that can change, move, or overwrite files without confirmation.
Install only if you want a local credential-auditing tool that can inspect sensitive files. Prefer audit, exposure, inventory, or status first; avoid protect, fix-permissions, quarantine, and unquarantine unless you explicitly want file permissions changed or files moved/restored. Run it in a trusted environment and treat its output as sensitive because it can report paths and masked credential matches from shell history, shell config, and git config.