This skill is an architecture-document assistant, but it sends potentially sensitive project materials to an external MCP service using an embedded bearer token and limited user-facing disclosure.
Review this carefully before installing. Use it only if you are comfortable sending architecture documents, requirements, API details, and deployment information to the listed external MCP service. The publisher should rotate the exposed token, remove secrets from the package, restrict allowed tool calls, and add an explicit consent and data-handling notice before this should be treated as low risk.