This skill is meant to publish to Tilda, but it gives an agent live website publishing access while storing the account password locally and relying on broad, weakly confirmed actions.
Install only in a private workspace if you are comfortable giving the agent access to a Tilda account that can publish live site changes. Use a dedicated or least-privileged account if possible, keep .env and session files out of source control and backups, approve any npm/npx installation explicitly, delete debug screenshots/logs after troubleshooting, and require the agent to confirm the exact Tilda project, page, destination, and content before saving or publishing.