The skill mostly does what it advertises, but it sends credentials and media over plaintext HTTP and creates default background watchers that can read session data and post results back into chats or transcripts.
Install only if you trust the EasyClaw relay and are comfortable sending prompts, uploaded media, API tokens, and task results through this skill. Prefer HTTPS-only configuration, avoid sensitive reference files, use --no-watch when background delivery is not needed, inspect created cron jobs, and rotate any credentials that may have been exposed via HTTP, query strings, or command-line arguments.