SkillBoss mostly matches its app and AI gateway purpose, but it uses broad local and remote authority with credential persistence and an automatic updater path that can run an uninspected shell script.
Install only if you are comfortable with a Bash-based gateway that sends prompts, files, deployment bundles, emails/SMS requests, product changes, and payment setup requests to SkillBoss/HeyBoss services. Keep API keys out of client-side code and public repositories, review any install/update.sh before allowing updates, and use the deployment/product/email/SMS commands only for projects and recipients you explicitly intend to modify or contact.