This stroke-screening skill performs the advertised cloud analysis, but it also silently creates/reuses identities, stores tokens locally, and handles sensitive health media without clear user consent boundaries.
Review before installing. Use this only if you are comfortable sending facial images/videos, optional physiological values, and an internally resolved user identity to the configured backend service, and if you accept local token/profile persistence in the workspace data directory. The publisher should add an explicit privacy and consent step, fix the pet-health documentation mismatch, remove dev/private endpoint defaults, and provide clear controls for account linkage and stored-token deletion.