The skill’s main goal is coherent, but it gives itself broad update, file-modification, credential-reuse, and platform-management powers without enough user control.
Review before installing. Use it only in a workspace where you are comfortable with the agent reading project files, writing configuration, and calling VibeLock APIs. Do not allow automatic skill updates unless you can verify the downloaded package, and avoid storing long-lived API tokens in plaintext project files; prefer short-lived or manually supplied tokens and confirm every marketplace, deletion, license, renewal, or telemetry action.