Atlas / MCP servers / davidmosiah / Google Health

Google HealthCAUTION

mcp/davidmosiah/google-health

Local-first MCP server for Google Health API v4 (Fitbit + Pixel Watch) — Claude/Cursor/Hermes

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
26 24r · 1w · 1d
Transport
stdio · streamable-http
License
MIT
Stars
66
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Google Health MCP

Read user-authorized Google Health API v4 data — Fitbit, Pixel Watch and partners — locally via OAuth. Beta. Local-first MCP server — tokens never leave your machine.

Read from source at commit f5f0c1576ec9OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add google-health-mcp-unofficial --env GOOGLE_HEALTH_CLIENT_SECRET=${GOOGLE_HEALTH_CLIENT_SECRET} -- npx -y [email protected]
03

Exposed tools (26)

24 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
google_health_agent_manifestread
google_health_cache_statusread
google_health_capabilitiesread
google_health_connection_statusread
google_health_daily_rollupread
google_health_daily_summaryread
google_health_data_inventoryread
google_health_data_type_coverageread
google_health_demoread
google_health_exchange_coderead
google_health_get_auth_urlread
google_health_get_identityread
google_health_get_profileread
google_health_get_settingsread
google_health_list_data_pointsread
google_health_list_data_typesread
google_health_onboardingread
google_health_privacy_auditread
google_health_profile_getread
google_health_profile_updatewrite
google_health_quickstartread
google_health_reconcile_data_pointsread
google_health_revoke_accessdestructive
google_health_rollupread
google_health_weekly_summaryread
google_health_wellness_contextread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/auth.ts:268
console.log(`  Token file:  ${output.token_path}`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
google_health_revoke_access
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:75
# GET  http://127.0.0.1:3000/health
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:76
# POST http://127.0.0.1:3000/mcp   (sessionless)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:105
Create a Google Cloud OAuth client, enable the Google Health API, and add the redirect `http://127.0.0.1:3000/callback`. Then:
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:243
http://127.0.0.1:3000/callback
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:268
npx -y google-health-mcp-unofficial auth --code "http://127.0.0.1:3000/callback?code=..."
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, better-sqlite3, cors, delx-mcp-kit, express, zod, @types/better-sqlite3, @types/cors
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f5f0c1576ec9full audit observations/trust-audit/mcp-server/davidmosiah__google-health.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f5f0c1576ec9CAUTIONB89first audit
06

Questions

What is the Google Health MCP server?

Local-first MCP server for Google Health API v4 (Fitbit + Pixel Watch) — Claude/Cursor/Hermes

What tools does Google Health expose?

26 in total: 24 read-only, 1 that write, and 1 that can delete or overwrite (google_health_revoke_access). Every one is listed on this page with its risk.

Is Google Health safe to connect to an agent?

With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Google Health need?

It reads GOOGLE_HEALTH_AUTH_TIMEOUT_MS and GOOGLE_HEALTH_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Google Health run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as google-health-mcp-unofficial at 0.7.8.

How current is this page?

The grade is for one exact copy of the source (f5f0c1576ec9), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement