This skill is mostly a trust-score lookup, but it also includes undocumented scripts that can use a GitHub login to create persistent trust-channel repos and commit handshake secrets.
Treat this as Review rather than a simple read-only reputation checker. The public curl examples are coherent, but do not run the bundled shell scripts unless you explicitly want them to use your GitHub account, create a private repo, commit handshake material, and maintain a persistent inter-agent channel. If already run, inspect git remotes for embedded tokens and rotate any exposed GitHub credentials or handshake seeds.