This appears to be a real P2P agent messaging skill, but it needs Review because it grants broad local and VPS control while handling secrets and public endpoints unsafely.
Install only if you are comfortable giving this skill broad command execution, SSH access to a VPS, persistent background services, and access to OpenClaw/P2P secrets. Use a dedicated VPS and SSH key, rotate any hooks/API/admin credentials after testing, inspect the deploy source before running auto-install, and avoid using it for sensitive files until command injection, plaintext secret storage, endpoint authentication, and file-transfer approval issues are fixed.