This is a local code-review skill whose risky-looking code is mostly detection patterns, examples, and intentionally vulnerable fixtures, but users should treat reports as sensitive before sharing them.
Install only if you are comfortable letting it read the files or directories you ask it to review. Keep generated reports private unless you have reviewed them for secrets and sensitive code, and use Slack, email, GitHub, cron, pre-commit, or API server examples only with explicit team approval and appropriate redaction/security controls.