The skill is mostly a Ghost publishing helper, but its docs expand beyond the stated Admin API-only scope into browser code injection, external webhook/data sharing, persistent automation, and broader credentials.
Review this skill carefully before installing. Use a dedicated, revocable Ghost integration key where possible, avoid owner tokens unless a specific task requires them, do not allow autonomous browser code injection or settings changes, require explicit confirmation before publishing or emailing subscribers, and do not enable webhooks or cron publishing until you have scoped events, payloads, authentication, and rollback procedures.