The skill has a real OppHub purpose, but it grants and normalizes broad token, cron, local-memory, file-upload, and production-ops access that is not clearly scoped for users.
Review before installing. Use this only in a workspace where OppHub may receive company profiles, contract-derived data, and search-derived content. Avoid running discovery against private memory/wiki sources unless you explicitly want that context used. The publisher should remove bundled production docs/secrets, redact token diagnostics, add explicit upload and cron confirmations, and document exactly what leaves the device.