The skill’s CSO publishing workflow is mostly coherent, but its installer makes broad lasting system changes and runs remote code with too little user control.
Review the installer before running it. Prefer a manual install that keeps npm’s registry unchanged, avoids piping remote scripts into shells, and registers the skill only in the assistant you intend to use. Treat CSO credentials, OAuth links, json-out account snapshots, uploaded media, and publish actions as sensitive; confirm target accounts and content before any upload, account change, planning generation, retry, delete, or publish operation.