This WHOOP fitness skill is mostly purpose-aligned, but it handles sensitive health data, credentials, recurring reports, and external LLM calls with enough scoping and disclosure gaps that users should review it carefully before installing.
Install only if you are comfortable granting access to WHOOP recovery, sleep, HRV, workout, profile, and body data. Treat the local token/API-key files as sensitive, review file permissions, and delete or rotate credentials if you uninstall. Configure an LLM only if you accept that health summaries and prompts may be sent to that provider, and be cautious using the cron/push scripts because some paths and user IDs appear environment-specific.