This appears to be a real skill-evaluation framework, but it needs Review because normal use can execute local or remote skill code and custom scorer code with under-scoped trust boundaries.
Install only if you are comfortable running a tool that evaluates and may execute skill code. Use it in an isolated workspace, prefer Docker sandboxing with controlled network egress, avoid exposing broad API keys or secrets, review all skill entrypoints and custom scorer paths before running, and treat HTTP/MCP/LLM endpoints as places where benchmark data may leave your machine.