The skill is coherent, but it teaches scripts to capture and reuse a live OneHome login token to access private real-estate data without enough credential-safety guardrails.
Install only if you are authorized to access the OneHome account/session being queried and you trust the fpx CLI, Transporter extension, and anyone with access to the machine. Treat the bearer token and generated JSON files like account credentials: do not share logs or screenshots containing them, avoid shared machines, clean up temporary files, and prefer a sanctioned API or safer delegated-auth flow where available.