HeartFlow is a legitimate-looking local AI guardrail, but it asks for review because its real runtime stores state, manages credentials, and exposes a large localhost MCP surface more broadly than its read-only rule-engine framing suggests.
Review this skill as a stateful local MCP service, not just a passive text checker. Install only if you are comfortable with local memory/log files, a localhost authenticated server, plaintext .env token handling, and a broad tool surface; run it in a contained project and set explicit token, path-guard, persistence, and network settings before use.