1. Uses plaintext private keys in memory and has no support for yubikeys, nitrokeys, or other smartcards
2. Binary/commits are not signed, so there is no supply chain integrity to build or install this. Readme recommends blind execution of crypto code off the internet that may or may not be what the authors actually wrote.
3. No code review seems to be happening per git history, at least no signed code review publicly accessible.
4. Breaks OpenPGP spec and conventions for seemingly no reasons at all?
5. Rightfully mentions that you should not put a plaintext password on the CLI, then proceeds to recommend you use pass in a way that puts the password back in plaintext on the CLI via a subshell which is still totally plaintext in the proc filesystem, in ps, etc, to all processes on the system running as any user. (Unless you mount /proc with hidepid=2 but this is never a default and almost no one does it)
6. No support for Git, ssh, etc so you still need to use Sequoia or GnuPG anyway (as readme points out)
This seems like a really fun and educational hobby project, but I would not seriously suggest anyone use this for anything actually security critical in its current state.
To anyone that wants this functionality best-effort safely today: Get a Yubikey 5 or Nitrokey 3, put an ECC PGP keychain on it, enable touch requirements for all slots, export your keys on keyoxide, then set it up with git, ssh, pass, your email client of choice, etc.
Today you can do all this with GnuPG though admittedly this is a rotting, buggy, and badly maintained c codebase. The well tested Rust replacement, Sequoia, is almost at feature parity now, so keep a close eye on that or try it today instead and see if it already meets your needs.