This skill is not obviously harmful, but it needs review because it creates persistent agent identity and authentication state with some sensitive flows that are under-scoped or inconsistent.
Review before installing. Use only if you are comfortable with persistent local identity files, memory-chain logs, key pins, gateway hooks, and trust-score effects under ~/.openclaw. Protect backups and exports, prefer keychains or secret managers over environment variables for passphrases, verify any recovery phrase prompt is part of a local import/export flow, and inspect or obtain the actual implementation before relying on it for authentication.