This is a plausible trust-and-memory assistant, but it has a real command-injection risk and stores or sends sensitive prompt data with weak scoping and disclosure.
Review before installing. Use only in an isolated environment unless run.mjs is patched to use execFile/spawn with argument arrays and no shell. Avoid entering secrets or sensitive personal, medical, business, or security data unless persistence is disabled or the memory/trust files are redacted and managed. Prefer a trusted local or allowlisted model endpoint, and verify what data will be sent before setting API keys.