The skill fits its DevKit installation purpose, but it needs Review because it combines cloud provisioning, root SSH installation, public network exposure, weak trust checks, and explicit guard-bypass polling guidance.
Install only if you are comfortable granting cloud credentials that can create ECS/EIP/security-group resources and use KMS decrypt. Before running it, restrict security group sources to your IP or VPN instead of 0.0.0.0/0, confirm all package sources, rotate or protect the DevKit admin password and logs, verify SSH host keys, and run KMS cleanup after successful verification. I found no artifact-backed evidence of hidden exfiltration or unrelated destructive behavior, but the defaults are too powerful and too loosely scoped for automatic trust.