This legacy OAuth refresher is not clearly malicious, but it needs review because it copies Claude tokens, modifies credential stores and auth files, installs a persistent macOS job, and auto-detects messaging targets.
Install only if you specifically need this legacy refresher and understand that it will handle live Claude OAuth tokens. Prefer Clawdbot's native Claude OAuth setup if available. Before running install.sh, review the launchd service, disable or manually configure notifications, protect auth-profiles.json, and be aware that the skill copies refresh credentials out of Keychain and keeps a background refresher running.