The skill is mostly a disclosed AI testing toolkit, but some security-audit outputs are simulated while presented as compliance results, and online tests can send realistic sensitive test data or retrieved documents to configured endpoints without clear warning.
Review this before installing if you plan to use it for security or compliance decisions. Keep endpoints local or trusted, replace the realistic ID/phone fixtures with clearly fake values, avoid sending private RAG corpus text to third-party judge models, and do not rely on the MCP compliance score as verified evidence without improving those checks.