The skill does compress images through a remote API, but it also reads broad .env files, persists API keys, and sends a machine-derived device identifier with insufficient user-facing disclosure.
Review this skill before installing. It sends image contents to a third-party NX API/CDN, may store your NX API key in a project .env file, searches parent and home .env files, and sends a stable device identifier derived from the machine unless you override it with --client or NX_CLIENT_ID. Avoid using it on sensitive images or in directories with unrelated secrets unless those behaviors are acceptable.