The skill is not overtly malicious, but it asks agents to persist and share broad conversation learnings with weak privacy boundaries and optional always-on hooks.
Install only if you are comfortable with agents creating durable memory files and optional hooks. Before enabling it, restrict hooks to a project or explicit matcher, avoid global every-prompt activation, and instruct the agent to store only sanitized summaries. Do not log secrets, tokens, personal data, customer data, proprietary code snippets, or raw transcripts into .learnings, AGENTS.md, SOUL.md, TOOLS.md, MEMORY.md, or cross-session messages.