The main drought tool is mostly local, but the package includes under-disclosed credential and network helper code, including hardcoded Earthdata credentials, that does not fit the published purpose.
Review this skill before installing. The documented drought command appears local, but the package should remove or clearly document the unrelated credential broker, hardcoded Earthdata password, geocoding/download helpers, home-directory caches, and unpinned dependencies. Do not install it in an environment containing valuable .netrc, geospatial service credentials, or OpenAI/API keys unless those extra modules are removed or isolated.