The skill is a real 1C RAG assistant, but it also includes under-scoped automation that can monitor session logs, send data to fixed services, publish uploaded images, access calendar data, and expose host details.
Review before installing. Use only in an environment you control, rotate the exposed Qdrant key, and remove or separately permission the calendar, email/report, Ollama, system-status, Python/DevOps, public image-serving, and ingestion features unless you explicitly want them. Do not upload screenshots, PDFs, or 1C business documents unless you are comfortable with their contents and metadata being processed by the configured webhooks and Telegram flow.