This package needs Review because its visible scanner skill is bundled with unrelated higher-risk tools such as sandbox code execution, financial/NFT workflows, and indefinite monitoring.
Install only if you intentionally want a broad experimental multi-skill bundle, not just a vulnerability scanner. Review or remove the sandbox script executor, automatic dependency-install guidance, indefinite watchdog monitoring, financial/NFT recommendation workflows, and logged-in browser workflows. Do not provide real API tokens, private documents, or logged-in service access unless you understand what the agent may read, run, or display.