The code seems to be mainly a static Eleventy site, plus some installation scripts (bash/Powershell). Honestly, I’d personally put in the effort and avoid using third-party scripts in your most crucial application.
I am struggling to produce a valid threat model for this tool: why patch browsers that are known to be untrustworthy, instead of running a trustworthy browser from the start?
Firefox is the only recommended PG browser for which this tool works, and we’ve already listed instructions for performing much of this hardening