This skill appears purpose-built for SubsTracker, but it uses account credentials, persistent session cookies, broad auto-invocation, deletes, and notification secrets in ways users should review before installing.
Install only if you trust the SubsTracker server and will run this skill from trusted directories. Keep all `SUBSTRACKER_*` values in one protected config source, avoid cwd overrides, treat `.env` and CLI flags as secrets, clear the saved cookie when changing servers, and require explicit user confirmation before deletes, password changes, config updates, or notification tests.