The skill is mostly an audit and recommendation helper, but it also scans sensitive session histories and one helper script runs local diagnostic commands beyond the read-only description.
Install only if you are comfortable with a skill auditing local skills, plugins, project files, MCP config, and session history. Before running extract_usage_signals.py, scope the session directories and consider removing or disabling the headroom live probe unless you trust your PATH and local headroom binary. Treat lifecycle/action outputs as plans that require your explicit confirmation, backups, and review before any agent changes files or configuration.