This research skill is not clearly malicious, but it uses high-impact local session credentials and persists research data in ways users should review before installing.
Install only if you are comfortable with a research tool using local X browser cookies or AUTH_TOKEN/CT0, reading Codex login credentials as an OpenAI fallback, sending search topics/URLs to third-party services, and retaining reports/findings locally. Prefer explicit API keys where possible, keep the secrets file private, avoid sensitive topics unless you are comfortable with persistence and provider disclosure, and review/delete the local data directory periodically.