The skill presents itself as a cognitive engine, but its artifacts describe broader and under-disclosed behavior including background services, broad memory, external model fallback, and possible self-modifying workflows.
Review this skill carefully before installing. The main issue is not a malware signature or VirusTotal result, but that the artifacts describe significant local runtime authority, persistence, memory retention, and possible external data flow without consistent disclosure. Only use it in a contained environment after confirming how the daemon starts and stops, what data is stored, when external LLM calls happen, and whether any self-updating or commit/push behavior is disabled or explicitly user-approved.