NutritionSAFE
A remote MCP server for personal nutrition tracking — log meals, track macros, and review nutrition history through conversation.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A remote MCP server for personal nutrition tracking — log meals with calories, macros, fiber, total and added sugar and caffeine, log water, body weight and body measurements, review nutrition history, and import an existing food diary from another app, all through conversation. Alcohol tracking is opt-in and off by default.
[Help me pay for the servers on Patreon][patreon]
[patreon]: https://patreon.com/akutishevskyi
Table of Contents
- Quick Start
- Demo
- Tech Stack
- MCP Tools
- MCP Resources
- Self-hosting
- 0. Get the code
- 1. Supabase setup
- 2. Environment variables
- 3. Google sign-in (optional)
- Development
- Testing and quality
- Connect to Claude.ai
- Apple Health sync
- Troubleshooting
- API Endpoints
- Deploy
- Support & security
- Data sources
- License
Quick Start
Already hosted and ready to use — just connect it to your MCP client:
https://nutrition-mcp.com/mcp
On Claude.ai: open Nutrition MCP in the Claude directory and click Connect (see Connect to Claude.ai below)
On first connect, sign in with Google or enter an email and password and choose Create account. Your data persists across reconnections. Trouble connecting? See Troubleshooting.
By connecting you agree to the Terms of Service; how your data is handled is in the Privacy Policy.
Switching from another tracker? See the nutrition-app alternatives — ho
053c4c6ab2bdOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add nutrition-mcp --env GOOGLE_CLIENT_SECRET=${GOOGLE_CLIENT_SECRET} --env OAUTH_CLIENT_ID=${OAUTH_CLIENT_ID} --env OAUTH_CLIENT_SECRET=${OAUTH_CLIENT_SECRET} --env PATREON_ACCESS_TOKEN=${PATREON_ACCESS_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"nutrition-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GOOGLE_CLIENT_SECRET": "${GOOGLE_CLIENT_SECRET}",
"OAUTH_CLIENT_ID": "${OAUTH_CLIENT_ID}",
"OAUTH_CLIENT_SECRET": "${OAUTH_CLIENT_SECRET}",
"PATREON_ACCESS_TOKEN": "${PATREON_ACCESS_TOKEN}"
}
}
}
}Exposed tools (41)
24 read · 12 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
bulk_import_meals | write | |
delete_account | destructive | |
delete_body_measurement | destructive | |
delete_meal | destructive | |
delete_water | destructive | |
delete_weight | destructive | |
export_all_data | read | |
get_body_measurements | read | |
get_current_time | read | |
get_goal_progress | read | |
get_meal_patterns | read | |
get_meals_by_date | read | |
get_meals_by_date_range | read | |
get_meals_today | read | |
get_nutrition_goals | read | |
get_nutrition_summary | read | |
get_profile | read | |
get_trends | read | |
get_water_by_date | read | |
get_water_today | read | |
get_weight_by_date | read | |
get_weight_by_date_range | read | |
get_weight_today | read | |
get_weight_trends | read | |
log_body_measurement | read | |
log_meal | read | |
log_water | read | |
log_weight | read | |
lookup_barcode | read | |
search_meals | read | |
set_alcohol_tracking | write | |
set_language | write | |
set_length_unit | write | |
set_nutrition_goals | write | |
set_timezone | write | |
set_weight_unit | write | |
set_widget_display | write | |
start_meal_import | write | |
update_body_measurement | write | |
update_meal | write | |
update_weight | write |
Trust audit
SAFEgrade C · trust 80/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
delete_account, delete_body_measurement, delete_meal, delete_water, delete_weight
.prettierignore
const factory = new Function(
const factory = new Function(
const factory = new Function(
const api = new Function(
const factory = new Function(
const { getWidgetHtml } = await import("../../src/widgets");const { getWidgetHtml } = await import("../../src/widgets");import { WIDGET_STRINGS, WIDGET_STRINGS_EN } from "../../src/copy/widgets";const { getWidgetHtml } = await import("../../src/widgets");const { MEAL_BREAKDOWN_TOP_N } = await import("../../src/widgets");["http://127.0.0.1:51789/cb", "loopback"],
"https://192.0.2.1/cb",
"http://127.0.0.1:51789/cb",
"http://127.0.0.1:1111/callback",
"http://127.0.0.1:2222/callback",
expect(normalizeHeader("B12 (μg)")).toBe(normalizeHeader("B12 (ug)"));"https://clаude.ai/cb", // Cyrillic "а"
expect(stripBom("A")).toBe("A");expect(stripBom("AB")).toBe("AB");@modelcontextprotocol/server, @supabase/supabase-js, hono, prettier, zod, @modelcontextprotocol/client, @types/bun
**Styling — reuse the shared design language.** All widgets share one look (Apple-like neutral surfaces, brand green accent, theme tokens, one compact card per widget, a donut gauge, thin metric bars,
`src/oauth.ts` is the authorization server every MCP client signs in through, and it is the one place in this repo where a mistake hands out someone else's account: until #148, `POST /register` gave e
- **One built-in first-party client: `HEALTH_SYNC_CLIENT` (`src/oauth-store.ts`, id `nutrition-mcp-health-sync`).** The Apple Health sync pairing signs in through the ordinary `/authorize` as this ser
Gates applied: no_behavioural_pass.
053c4c6ab2bdfull audit observations/trust-audit/mcp-server/akutishevsky__nutrition-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 053c4c6ab2bd | SAFE | C | 80 | first audit |
Questions
What is the Nutrition MCP server?
A remote MCP server for personal nutrition tracking — log meals, track macros, and review nutrition history through conversation.
What tools does Nutrition expose?
41 in total: 24 read-only, 12 that write, and 5 that can delete or overwrite (delete_account, delete_body_measurement, delete_meal, delete_water, delete_weight). Every one is listed on this page with its risk.
Is Nutrition safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it C (80/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Nutrition need?
It reads GOOGLE_CLIENT_SECRET, OAUTH_CLIENT_ID, OAUTH_CLIENT_SECRET, PATREON_ACCESS_TOKEN, PATREON_CLIENT_SECRET, PATREON_REFRESH_TOKEN and SUPABASE_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Nutrition run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as nutrition-mcp at 1.28.0.
How current is this page?
The grade is for one exact copy of the source (053c4c6ab2bd), read on 2026-10-08. The repository is watched and re-audited when it changes.