This skill is not deceptive, but it gives an agent broad Smartbi API authority, local token persistence, scheduled automation, and outbound messaging with incomplete safety guardrails.
Install only if you trust the Smartbi environment and the @smartbi/cli package, and use a least-privileged, revocable token. Before allowing actions, review every operationKey, request body, schedule, recipient, webhook URL, and outbound message content. Avoid using broad admin tokens, restrict ~/.smartbi/config.yaml permissions, rotate tokens if exposed, and do not let the agent fetch arbitrary external documentation links or activate recurring jobs without explicit approval.