This skill appears intended to help with browser login automation, but it exposes an authenticated browser session through a public tunnel with overly broad remote-control capabilities.
Review before installing. Use only in a trusted environment, do not share the cloudflared URL, close the tunnel immediately after login, avoid using it with sensitive accounts, and delete saved session state when finished. Prefer a version that binds to localhost, removes /eval and general remote-control endpoints, requires a strong access token, and clearly explains where session data is stored.