That GitHub account/repository looks very shady to me.
1. Some repo use GPL license, but none of them repository contain source code.
2. The text description appear to be AI generated.
I'm not familiar with flashing Pi, but the size seems quite large, at 1.35 GB.
Size doesn't matter if it's malicious by downloading the malware from internet.
There is a zipped source code on the release page, but it's just a copy of their GitHub, not the package itself as far as I can see.
Based on the description, the compressed file appear to be image file to be flashed rather than source code.