This is a coherent local multi-agent hub, but several runtime paths expose agent messages, tasks, or automation triggers without enough identity scoping or user review.
Install only in an environment where you trust the hub operator and participating agents. Bind it to localhost or a protected network, require Bearer auth on SSE and REST endpoints, enforce agent_id == authenticated identity for message/task APIs, avoid automatic task execution without a policy gate, do not point HUB_URL at untrusted servers, and do not run the test or DB-repair scripts against a real database without a backup.