This Tencent Cloud storage skill looks purpose-aligned rather than malicious, but it needs review because it can delete cloud objects, change bucket settings, call arbitrary Tencent CI APIs, and persist credentials locally.
Install only if you are comfortable giving this skill Tencent Cloud credentials with the exact COS/CI permissions it needs. Use a least-privilege sub-account or temporary STS credentials, avoid root or full-account keys, prefer non-persistent environment variables, and treat delete, batch delete, ACL/CORS changes, decrypt-env, and ci-request as sensitive operations that should be run only after explicit user review.