The main tree-counting command is local, but the package also ships under-disclosed network, credential-reading, cache, and hardcoded credential code that does not fit the stated offline orchard-counting purpose.
Review this package before installing. The tree-counting script itself appears local, but the bundled core should be reduced or separated: remove the hardcoded Earthdata credentials, rotate that account if real, delete or isolate unused credential/download/geocoding modules, and disclose or disable any network geocoding and home-directory cache behavior. Run it in a restricted environment if you only need the synthetic or local CHM workflow.