The main wildfire simulator appears local, but the package also includes undisclosed downloader, geocoder, and credential-handling code with hardcoded credentials, so it should be reviewed before installation.
Install only after reviewing or removing the vendored geoskill core pieces that are unrelated to wildfire modeling, especially credentials.py, safe_download.py, and network geocoding. Rotate the embedded Earthdata credentials if they are real, pin dependencies, and do not use this package in sensitive environments unless third-party geocoding and local credential access are disabled or clearly controlled.