The skill’s procurement analysis features fit its purpose, but it also includes an under-disclosed trial signup flow that collects a stable device fingerprint, sends it to a third party, and saves an API key locally.
Install only if you are comfortable with this provider receiving your procurement queries and, if you do not configure an API key yourself, with the skill asking to create a trial account using your OS, CPU architecture, and a hashed MAC-derived device identifier. Prefer configuring ZLBX_API_KEY manually and review/remove ~/.zlbx/config.json if you do not want a persistent local key.