This appears to be a legitimate Postiz automation skill, but it gives an agent broad power to post, upload media, and delete social content with weak confirmation and credential-safety guidance.
Install only if you want an agent to operate Postiz on real connected social accounts. Require the agent to show the exact content, media files, target platform/account, integration IDs, schedule, and any deletion target before running create, upload, connect, or delete commands. Prefer drafts or test accounts first, avoid storing API keys in shell profiles, do not print secrets in terminals, and remove OAuth credentials with `postiz auth:logout` when persistent access is not needed.