The skill is a disclosed note-research workflow, but it also installs and manages a broad shared Beatra authorization, silent self-updates, upload capability, telemetry, and credential lifecycle controls that go well beyond note research.
Install only if you are comfortable granting this package a broad shared Beatra device authorization rather than a narrow note-only permission. Before use, review the Beatra account, billing, and trust assumptions, consider running `python3 scripts/mcp_client.py update --auto off`, and confirm every paid Xiaohongshu lookup before it runs. Avoid installing in environments where silent code updates, shared bearer credentials, local skill inventory, upload capability, or wallet/media/task scopes are not acceptable.