60
/ 100
27 days ago
glama

Delx Living Body

Meta-MCP that auto-detects installed wellness connectors and composes them into one body data layer.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
6 tools verified — handlers match their declared behaviour
6 read-only tools verified — handlers contain no write/delete/exec
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: WHOOP_CLIENT_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.21.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.21.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.21.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configDELX_LIVING_BODY_CACHE_PATH~/.delx-living-body/cache.sqlite Override cache path
configDELX_LIVING_BODY_CHILD_OVERRIDE_GARMIN
configDELX_LIVING_BODY_CHILD_OVERRIDE_OURA
configDELX_LIVING_BODY_CHILD_OVERRIDE_WHOOP
configDELX_LIVING_BODY_DETECT_TTLDetection results cache for 60s ().
configDELX_LIVING_BODY_NO_CACHECache lives at ~/.delx-living-body/cache.sqlite (chmod 600), 5 min TTL. Disable with =true.
configDELX_LIVING_BODY_NPM_RUNNERnpx Override npm runner for child spawning
configLIVING_BODY_MCP_ALLOWED_ORIGIN
configLIVING_BODY_MCP_HOST/ LIVING_BODY_MCP_PORT 127.0.0.1 / 3030 HTTP transport bind address
configLIVING_BODY_MCP_PORTLIVING_BODY_MCP_HOST / 127.0.0.1 / 3030 HTTP transport bind address
configLIVING_BODY_MCP_TRANSPORT
configSTUB_BB
configSTUB_LOAD
configSTUB_RECOVERY
configSTUB_SLEEP
configSTUB_VENDOR
🔐 secretWHOOP_CLIENT_SECRET
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/davidmosiah-delx-living-body-nb3zhn)](https://m8ven.ai/mcp/davidmosiah-delx-living-body-nb3zhn)
commit: dacbcf33d1b441a43147bae4daa8feddbeb9a548
code hash: 16ca170d117c2e7818a86530397735dac2a9de32e37e5421cf6c62210b73f300
verified: 7/4/2026, 9:12:02 AM
view raw JSON →