fitbit-google-health-mcp (rickygarim/fitbit-google-health-mcp) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 17 tools. No publisher has claimed this listing.

D
Caution
56/100

fitbit-google-health-mcp

Read-only MCP access to Fitbit-synced health data through Google Health API v4. Provides tools for metrics, summaries, trends, and data quality without write or arbitrary HTTP operations.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

rickygarim

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 1 credential: GOOGLE_CLIENT_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes17 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

list_available_metrics

List Google Health API v4 data types available through this Fitbit-synced Google Health integration. This is not a direct Fitbit Web API catalog.

get_data_source_info

Explain exactly where this server gets health data, which API it uses, its read-only boundaries, and known availability limitations. Call this before interpreting metric results.

get_metrics

Read one or more Google Health API v4 metric types for a date/time range. Use list_available_metrics for supported names. Returns raw normalized API records and source metadata.

get_recent_metrics

Read recent Fitbit metrics with a safe default 7-day range. Each metric is isolated so unsupported or unavailable types do not fail the whole response.

get_health_snapshot

Return a compact current-day Fitbit snapshot including activity, heart rate, body composition, sleep, freshness, and unavailable metrics.

get_trends

Calculate numeric trend summaries for recent Fitbit metrics: count, average, minimum, maximum, first value, last value, and percent change where possible.

get_sleep_summary

Return normalized sleep sessions and stage totals for a recent date range.

compare_periods

Compare a recent period with the immediately preceding period using daily numeric values and percent changes.

get_data_quality

Diagnose recent Fitbit data coverage, missing records, source provenance, and API-limited metrics without treating missing data as zero.

get_activity_summary

Summarize recent movement, distance, calories, floors, and heart-rate-zone activity.

get_recovery_summary

Summarize sleep, heart rate, HRV, oxygen saturation, and respiratory-rate data for informational recovery context.

get_body_metrics

Summarize recent weight, body-fat, temperature, height, and blood-glucose records with normalized units and source metadata.

get_sync_status

Check connected Fitbit/Google Health account metadata, paired devices, and whether core metrics have recent data.

get_profile

Read the connected Google Health/Fitbit profile and identity metadata.

get_devices

List devices paired with the connected Google Health account, including the Fitbit Air when exposed by the account.

get_settings

Read connected Fitbit/Google Health settings and configured preferences.

get_daily_summary

Read the most useful daily Fitbit metrics in one call: steps, calories, distance, active minutes, active zone minutes, resting heart rate, HRV, oxygen saturation, respiratory rate, sleep, and weight where available.

// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.17.5GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.17.5GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.17.5GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configFITBIT_MCP_PORT
configFITBIT_MCP_TOKEN_PATH
configGOOGLE_CLIENT_ID
🔐 secretGOOGLE_CLIENT_SECRET
configXDG_CONFIG_HOME
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

17/17 tools missing one or more hints — list_available_metrics (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_data_source_info (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_metrics (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +14 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

11/17 tool handlers declare input schemas (65%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

12/17 tool handlers wrap calls in try/catch (71%)

Wrap each tool handler body in try/catch and return a structured error response.

Tool test coverage

Only 0/17 tools referenced in tests (0%)

Write tests that reference each tool by name so every tool has at least one test.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.17.5 (high), @modelcontextprotocol/sdk@1.17.5 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/rickygarim/fitbit-google-health-mcp?variant=verified)](https://m8ven.ai/mcp/rickygarim/fitbit-google-health-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: ebb0ea599241d21a320fbce44cc5ec6faa17f16c
code hash: 3c811e47cd2c33fb1bd0cbe314d89be42591977f97aba569c5464eeb497b2895
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client