This skill is a real health-data sync integration, but it asks the agent to publish and persist a health-data webhook with limited user confirmation and includes a remote API query script that conflicts with local-only claims.
Install only if you are comfortable with an agent creating a public HTTPS endpoint for health data and keeping a webhook running in the background. Before use, require explicit approval for tunnel setup and persistence, set a strong VITAVAULT_SYNC_TOKEN, avoid unauthenticated webhook runs, and review scripts/query.py because it uses a remote API endpoint despite local-only privacy language.