This skill mostly matches its ecommerce content purpose, but its helper runs an unpinned npm package with the full local environment, which can expose unrelated secrets if the package or its dependencies change or are compromised.
Review this before installing in any environment that contains cloud keys, CI tokens, production credentials, or sensitive business data. Prefer pinning the npm package version, running it with a minimal environment containing only the required token/API URL/PATH, and requiring explicit user confirmation before any task that uploads local media or spends credits.