This Zalo automation skill is coherent, but it needs review because it can read and forward private messages, expose login/webhook/MCP endpoints, store sensitive logs and credentials, and send account messages with limited safety guidance.
Review carefully before installing. Use it only with accounts and Official Accounts you control, require explicit confirmation before sending messages or exporting credentials, avoid broad history searches, prefer localhost or authenticated HTTPS endpoints, do not use --no-verify on exposed webhooks, protect credential and log files, and avoid forwarding message payloads to third-party automation services unless users have approved that data flow.