The skill is transparent about local LLM governance, but it can change or delete local models and policy without a built-in read-only mode or approval gate.
Install only in an environment where the agent's account is allowed to manage the target local LLM runtime. For observe-only use, run it against a runtime/account that cannot modify the model store or expose only scan/observe tools. Treat ~/.ai-guardian as sensitive local state, and avoid long-lived master passwords in environment variables where shell history, child processes, CI logs, or process inspection may expose them.