This does not look like confirmed malware, but it exposes broad local memory and code/command execution capabilities that are not fully disclosed by the skill description.
Install only if you want a local, persistent memory/cognitive engine and are comfortable with it storing conversation-derived data and exposing local services. Before enabling it, review or disable memory injection, MCP/daemon startup, and especially codeExecutor/selfInitiator routes; set SHUTDOWN_TOKEN if using the daemon; avoid storing secrets or sensitive personal data in its memory files.