This memory skill is not clearly malicious, but it handles private memories, API keys, GitHub sync, and persistent shell changes with enough scoping and credential-handling problems that users should review it carefully before installing.
Install only if you are comfortable with a memory tool that can read and write local memory files, index private notes, call external embedding providers, and sync memory content through GitHub. Prefer manual install over curl-to-bash, use --no-shell-rc, avoid storing API keys in shell startup files, use a private dedicated repository, review the remote URL before syncing, and do not store secrets or highly sensitive personal data in the memory repository.