← Back to search

io.github.davidmosiah/polarmcp

davidmosiah Scanned 1h ago

Privacy-first MCP server for Polar AccessLink — health, sleep and training data.

C
70.8 / 100

Versions

0.3.12latest
Jul 30, 2026
0.3.11
Jul 30, 2026
0.3.10
Jul 17, 2026
0.3.9
Jul 16, 2026
0.3.8
Jul 16, 2026
+ show 13 moreshow less
0.3.7
Jul 15, 2026
0.3.6
Jul 8, 2026
0.3.5
May 24, 2026
0.3.4
May 20, 2026
0.3.3
May 20, 2026
0.3.2
May 19, 2026
0.3.1
May 11, 2026
0.3.0
May 11, 2026
0.2.0
May 11, 2026
0.1.3
May 6, 2026
0.1.2
May 4, 2026
0.1.1
May 4, 2026
0.1.0
May 4, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 19

polar_data_inventory
annotations: verified low

Inventory supported Polar data domains, auth scope requirements, privacy boundary and recommended first calls. Does not call Polar APIs or expose user data.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_agent_manifest
annotations: verified low

Machine-readable install, runtime and client guidance for AI agents. Does not call Polar or expose secrets.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_capabilities
annotations: verified low

Explain supported Polar data, privacy boundaries, recommended agent workflow and project links.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_quickstart
annotations: verified low

Personalized 3-step setup walkthrough for the human user. Adapts to current state (env vars set? token present? what's next?). Call this first when the user asks 'how do I connect Polar?'

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_demo
annotations: verified low

Returns realistic example payloads of polar_daily_summary, polar_wellness_context, and polar_list_nightly_recharge so agents see the contract before calling real Polar APIs.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_get_auth_url
annotations: verified low

Generate a Polar OAuth authorization URL. Use this first when no local token exists.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_exchange_code
annotations: verified low

Exchange a Polar OAuth authorization code for local tokens. Tokens are stored locally with 0600 permissions and are never returned. Requires explicit user action: the user must complete browser OAuth and supply the authorization code (agents must not invent codes).

readOnlyHint false openWorldHint true idempotentHint false destructiveHint false
polar_heart_series
annotations: verified low

Bounded heart-rate series from Polar continuous samples (agent-safe-series/v1).

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
polar_get_route
annotations: verified low

Load a Polar route by route id. Routes are GPS-sensitive; default privacy modes redact coordinates. Requires routes:read.

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
polar_connection_status
annotations: verified low

Check local Polar config, token file, Node version, privacy mode, cache readiness and optional MCP client readiness without calling Polar or exposing secrets.

response_format enum
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_cache_status
annotations: verified low

Show optional local SQLite cache status. Enable with POLAR_CACHE=sqlite or POLAR_CACHE=true.

response_format enum
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_privacy_audit
annotations: verified low

Return local privacy, cache, token-path and env-presence posture without revealing secret values.

response_format enum
readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_revoke_access
annotations: verified low

Delete the local Polar token file. Use only when the user explicitly wants to disconnect this MCP; revoke the remote grant from Polar if needed. Gated by explicit_user_intent: true (requires explicit user intent).

response_format enum
readOnlyHint false openWorldHint true idempotentHint false destructiveHint true
polar_daily_summary
annotations: verified low

Build a practical daily summary from Polar sleep, activity, Nightly Recharge and training data when available. Read-only and non-medical.

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
polar_weekly_summary
annotations: verified low

Build a weekly Polar scorecard with sleep, activity, Nightly Recharge, training load context, bottlenecks and actions. Read-only and non-medical.

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
polar_wellness_context
annotations: verified low

Normalize Polar Nightly Recharge, sleep and training load into the shared wellness_context shape for recommendation engines.

readOnlyHint true openWorldHint true idempotentHint true destructiveHint false
polar_profile_get
annotations: verified low

Read the canonical Delx Wellness profile shared with the other wellness MCP connectors (Nourish, Cycle Coach, CGM, etc.). Read-only. Profile stores only what the user typed during onboarding — never OAuth tokens, API keys, or biomarkers.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false
polar_profile_update
annotations: verified low

Persist a partial patch to the canonical Delx Wellness profile. Requires explicit_user_intent=true after the user confirms they want to save. Rejects secret-like fields (oauth, token, api_key, password, cookie, refresh, session).

readOnlyHint false openWorldHint false idempotentHint false destructiveHint false
polar_onboarding
annotations: verified low

Read-only. Return the 11-question Delx Wellness onboarding flow (en or pt-BR), the current shared profile, missing critical fields, and a cross-connector hint. Use this when the user starts a fresh wellness session and you need to fill out preferred_name, goals, devices, training context, nutrition, preferences, and safety.

readOnlyHint true openWorldHint false idempotentHint true destructiveHint false

Permissions 3

network medium
Server uses network capabilities via: fetch()
shell high
Server uses shell capabilities via: child_process, spawn(), spawnSync()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 58

info
Tool 'polar_exchange_code' annotations are consistent annotation_checker · 80%
info
Tool 'polar_heart_series' annotations are consistent annotation_checker · 80%
info
Tool 'polar_get_route' annotations are consistent annotation_checker · 80%
info
Tool 'polar_connection_status' annotations are consistent annotation_checker · 80%
info
Tool 'polar_cache_status' annotations are consistent annotation_checker · 80%
info
Tool 'polar_privacy_audit' annotations are consistent annotation_checker · 80%
info
Tool 'polar_agent_manifest' annotations are consistent annotation_checker · 80%
info
Tool 'polar_capabilities' annotations are consistent annotation_checker · 80%
info
Tool 'polar_quickstart' annotations are consistent annotation_checker · 80%
info
Tool 'polar_demo' annotations are consistent annotation_checker · 80%
info
Tool 'polar_get_auth_url' annotations are consistent annotation_checker · 80%
info
Tool 'polar_data_inventory' annotations are consistent annotation_checker · 80%
info
Tool 'polar_revoke_access' annotations are consistent annotation_checker · 80%
info
Tool 'polar_daily_summary' annotations are consistent annotation_checker · 80%
info
Tool 'polar_weekly_summary' annotations are consistent annotation_checker · 80%
info
Tool 'polar_wellness_context' annotations are consistent annotation_checker · 80%
info
Tool 'polar_profile_get' annotations are consistent annotation_checker · 80%
info
Tool 'polar_profile_update' annotations are consistent annotation_checker · 80%
info
Tool 'polar_onboarding' annotations are consistent annotation_checker · 80%
high
Hardcoded OAuth client secret in davidmosiah-polar-mcp-8bda652/scripts/date-range-test.mjs auth_checker · 95%
high
Hardcoded OAuth client secret in davidmosiah-polar-mcp-8bda652/scripts/endpoint-contract-test.mjs auth_checker · 95%
high
Hardcoded OAuth client secret in davidmosiah-polar-mcp-8bda652/scripts/activity-dedupe-test.mjs auth_checker · 95%
high
Hardcoded OAuth client secret in davidmosiah-polar-mcp-8bda652/scripts/agent-readiness-test.mjs auth_checker · 95%
high
Hardcoded OAuth client secret in davidmosiah-polar-mcp-8bda652/scripts/cli-ux-test.mjs auth_checker · 95%
medium
OAuth implementation without PKCE auth_checker · 75%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.21.0 (GHSA-345p-7cg4-v4c7) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.21.0 (GHSA-8r9q-7v3j-jr4g) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.21.0 (GHSA-w48q-cv73-mx4w) dependency_analyzer · 95%
info
package.json metadata manifest_parser · 100%
info
Tool: polar_data_inventory manifest_parser · 85%
info
Tool: polar_agent_manifest manifest_parser · 85%
info
Tool: polar_capabilities manifest_parser · 85%
info
Tool: polar_quickstart manifest_parser · 85%
info
Tool: polar_demo manifest_parser · 85%
info
Tool: polar_get_auth_url manifest_parser · 85%
info
Tool: polar_exchange_code manifest_parser · 85%
info
Tool: polar_heart_series manifest_parser · 85%
info
Tool: polar_get_route manifest_parser · 85%
info
Tool: polar_connection_status manifest_parser · 85%
info
Tool: polar_cache_status manifest_parser · 85%
info
Tool: polar_privacy_audit manifest_parser · 85%
info
Tool: polar_revoke_access manifest_parser · 85%
info
Tool: polar_daily_summary manifest_parser · 85%
info
Tool: polar_weekly_summary manifest_parser · 85%
info
Tool: polar_wellness_context manifest_parser · 85%
info
Tool: polar_profile_get manifest_parser · 85%
info
Tool: polar_profile_update manifest_parser · 85%
info
Tool: polar_onboarding manifest_parser · 85%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (7) manifest_parser · 80%
medium
OAuth authorization code flow without PKCE oauth_scope_analyzer · 75%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 170 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%