This is a real backup tool, but it needs review because some workflows can upload sensitive backup material, run restored scripts, and delete old backups without enough safeguards.
Install only after reviewing the scripts and deciding you are comfortable with local filesystem mutation, cron persistence, and GitHub upload behavior. Before using GitHub push, verify the repository is private and confirm whether an encrypted secrets archive will be included. Treat operational backups as sensitive because they include workspace memory, prompts, scripts, and skills. Run restore with --dry-run first, avoid --force unless you are in a controlled recovery procedure, and do not restore untrusted archives without inspecting or disabling the restored health-check script.