This skill is not malware-like, but it asks for broad persistent authority to change agent behavior, read private context, and send scheduled messages without a strong runtime consent gate.
Install only if you explicitly want an agent that changes AGENTS.md, keeps a persistent thread file, reads broad local/private context, and sends four proactive messages per day through your configured channel. Before enabling, review the AGENTS.md patch, limit QMD indexing to intended paths, keep sensitive vaults out unless you want them used, confirm the messaging channel is private, and know how to disable the cron jobs and delete CURIOSITY.md.