Atlas / MCP servers / akutishevsky / Withings

WithingsCAUTION

mcp/akutishevsky/withings-1

MCP server for Withings health data integration

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
14 14r · 0w · 0d
Transport
streamable-http
License
MIT
Stars
43
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[Help me pay for the servers on Patreon][patreon]

[patreon]: https://patreon.com/akutishevskyi?utmmedium=unknown&utmsource=joinlink&utmcampaign=creatorsharecreator&utmcontent=copyLink

[](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp) [](https://sonarcloud.io/summary/newcode?id=akutishevskywithings-mcp)

A Model Context Protocol (MCP) server that brings your Withings health data into Claude. Access your sleep patterns, body measurements, workouts, heart data, and more through natural conversation.

🔒 Privacy First: This is my personal

Read from source at commit d2f5e9963249OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add withings-mcp --env ENCRYPTION_SECRET=${ENCRYPTION_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "withings-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ENCRYPTION_SECRET": "${ENCRYPTION_SECRET}"
      }
    }
  }
}
03

Exposed tools (14)

14 read · 0 write · 0 destructive.

ToolRiskDescription
echoread
get_activityread
get_heart_signalread
get_hrvread
get_intraday_activityread
get_measuresread
get_sleepread
get_sleep_summaryread
get_stetho_signalread
get_user_devicesread
get_user_goalsread
get_workoutsread
list_heart_recordsread
list_stetho_recordsread
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (8)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/server/middleware.ts:39
logger.warn(`Authentication failed on ${method} ${path}: invalid or expired token`);
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
src/tools/heart.ts:65
"Get detailed ECG (electrocardiogram) signal data in micro-volts (μV) for a specific recording. Returns high-frequency waveform data with sampling information. Recording duration: BPM Core (20s), Move
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.github/workflows/test.yml:41
TEST_DATABASE_URL: postgres://postgres:postgres@localhost:5432/postgres
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/helpers/db.ts:12
*   TEST_DATABASE_URL=postgres://postgres:postgres@localhost:5432/postgres bun test
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@cfworker/json-schema, @modelcontextprotocol/hono, @modelcontextprotocol/server, @supabase/supabase-js, hono, zod, @types/bun, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:84
- **NO** tokens, access codes, or authentication credentials
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:238
- Nothing else needs restoring: tool handlers close over the MCP token alone and re-read all Withings credentials from Supabase per call
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
demo/demo.gif
demo/demo.gif
Why it matters. 2345770 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha d2f5e9963249full audit observations/trust-audit/mcp-server/akutishevsky__withings-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d2f5e9963249CAUTIONB86first audit
06

Questions

What is the Withings MCP server?

MCP server for Withings health data integration

What tools does Withings expose?

14 in total: 14 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Withings safe to connect to an agent?

With care. The audit graded it B (86/100) and found 8 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Withings need?

It reads ENCRYPTION_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Withings run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as withings-mcp at 2.1.0.

How current is this page?

The grade is for one exact copy of the source (d2f5e9963249), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement