Daily Rhythm appears purpose-built rather than malicious, but it needs review because it handles Google and Stripe data with recurring automation, plaintext local storage, and hard-coded workspace paths.
Review before installing. Edit the scripts to remove /Users/tom paths, enable only the integrations you need, use least-privilege Google and Stripe credentials, keep .env.stripe and OAuth token files out of version control, and add only cron jobs you know how to remove. Treat generated memory files as sensitive because they may contain task notes, personal reflections, revenue metrics, and customer identifiers.