fitbit-google-health-mcp (rickygarim/fitbit-google-health-mcp) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 17 tools. No publisher has claimed this listing.
Read-only MCP access to Fitbit-synced health data through Google Health API v4. Provides tools for metrics, summaries, trends, and data quality without write or arbitrary HTTP operations.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
rickygarim
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
list_available_metricsList Google Health API v4 data types available through this Fitbit-synced Google Health integration. This is not a direct Fitbit Web API catalog.
get_data_source_infoExplain exactly where this server gets health data, which API it uses, its read-only boundaries, and known availability limitations. Call this before interpreting metric results.
get_metricsRead one or more Google Health API v4 metric types for a date/time range. Use list_available_metrics for supported names. Returns raw normalized API records and source metadata.
get_recent_metricsRead recent Fitbit metrics with a safe default 7-day range. Each metric is isolated so unsupported or unavailable types do not fail the whole response.
get_health_snapshotReturn a compact current-day Fitbit snapshot including activity, heart rate, body composition, sleep, freshness, and unavailable metrics.
get_trendsCalculate numeric trend summaries for recent Fitbit metrics: count, average, minimum, maximum, first value, last value, and percent change where possible.
get_sleep_summaryReturn normalized sleep sessions and stage totals for a recent date range.
compare_periodsCompare a recent period with the immediately preceding period using daily numeric values and percent changes.
get_data_qualityDiagnose recent Fitbit data coverage, missing records, source provenance, and API-limited metrics without treating missing data as zero.
get_activity_summarySummarize recent movement, distance, calories, floors, and heart-rate-zone activity.
get_recovery_summarySummarize sleep, heart rate, HRV, oxygen saturation, and respiratory-rate data for informational recovery context.
get_body_metricsSummarize recent weight, body-fat, temperature, height, and blood-glucose records with normalized units and source metadata.
get_sync_statusCheck connected Fitbit/Google Health account metadata, paired devices, and whether core metrics have recent data.
get_profileRead the connected Google Health/Fitbit profile and identity metadata.
get_devicesList devices paired with the connected Google Health account, including the Fitbit Air when exposed by the account.
get_settingsRead connected Fitbit/Google Health settings and configured preferences.
get_daily_summaryRead the most useful daily Fitbit metrics in one call: steps, calories, distance, active minutes, active zone minutes, resting heart rate, HRV, oxygen saturation, respiratory rate, sleep, and weight where available.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
FITBIT_MCP_PORTFITBIT_MCP_TOKEN_PATHGOOGLE_CLIENT_IDGOOGLE_CLIENT_SECRETXDG_CONFIG_HOMETool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
17/17 tools missing one or more hints — list_available_metrics (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_data_source_info (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_metrics (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +14 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool inputs are validated
11/17 tool handlers declare input schemas (65%)
Declare an inputSchema with zod/joi/yup on every tool definition.
Tool handlers catch errors
12/17 tool handlers wrap calls in try/catch (71%)
Wrap each tool handler body in try/catch and return a structured error response.
Tool test coverage
Only 0/17 tools referenced in tests (0%)
Write tests that reference each tool by name so every tool has at least one test.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.17.5 (high), @modelcontextprotocol/sdk@1.17.5 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/rickygarim/fitbit-google-health-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check