I'm not going to advise others to take the survey because it's entirely possible that it will send a different keychain command to others, but I filled in the survey and the only keychain command that was sent to me was to sign a basic message, which is perfectly safe to do.
I used an alt account just in case, but there was no maliciousness involved that is apparent to me as of now.
Their code does not seem to do something tricky like that, for now. So they would have to put out a new version that does that. And it's defo possible.
It looks like they stopped issuing rewards so noise around this should stop soon.