This literature-analysis skill mostly matches its stated purpose, but it needs review because its graph editor exposes unauthenticated file-changing APIs and some LLM features can send PDF or graph content to third parties.
Review before installing. Run the graph server only on trusted machines and networks, preferably after changing it to bind to 127.0.0.1 and removing wildcard CORS. Avoid using private PDFs, unpublished manuscripts, confidential reading lists, or sensitive graph data with LLM/API features unless you are comfortable with that content leaving your machine. Keep backups of graph JSON files before using serve, remove-seed, or remove-paper, and avoid passing Zotero API keys directly on the command line.