This is a legitimate development workflow skill, but it gives the agent broad automatic code-changing authority and keeps a silent persistent project ledger without enough user control.
Install only if you are comfortable with an agent creating and modifying repository files, using git and authenticated gh, fetching API docs from URLs you provide, and maintaining a local flow/ledger.md memory file. Review generated flow/ files before committing, avoid storing secrets or sensitive business details in the ledger or .plan-flow.yml, and avoid or disable autopilot unless you explicitly want automatic workflow chaining.