The skill mostly matches its survey-management purpose, but its recommended setup/update paths can run high-impact installation actions that deserve review before use.
Install only if you trust the publisher and the Wenjuan account access this skill will receive. Prefer installing Node.js yourself from trusted channels, then use the locked npm dependencies, and avoid running setup.sh -y on a sensitive machine. Keep WENJUAN_HOST unset unless you intentionally use a trusted endpoint, store tokens in a private WENJUAN_TOKEN_DIR, and remove ~/.wenjuan and the skill .wenjuan/auth.json when finished on shared systems.