rerun-tests-when-changes — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited rerun-tests-when-changes (Rules) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server implementation that interfaces with the Hevy fitness tracking app and its API. This server enables AI assistants like Claude Desktop and Cursor to access and manage workout data, routines, and exercise templates through the Hevy API (requires PRO subscription).
Pick the workflow that fits your setup:
| Scenario | Command | Requirements |
|---|---|---|
| One-off stdio run | HEVY_API_KEY=sk_live... npx -y hevy-mcp | Node.js ≥ 26, Hevy API key |
| Local development | npm install && npm run build && npm start | .env with HEVY_API_KEY |
.nvmrc).You can launch the server directly without cloning:
HEVY_API_KEY=your_hevy_api_key_here npx -y hevy-mcp# Clone the repository
git clone https://github.com/chrisdoc/hevy-mcp.git
cd hevy-mcp
# Install dependencies
npm install
# Create .env and add your keys
cp .env.sample .env
# Edit .env and add your HEVY_API_KEYTo use this server with Claude Desktop, add the following to your claude_desktop_config.json:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"hevy-mcp": {
"command": "npx",
"args": ["-y", "hevy-mcp"],
"env": {
"HEVY_API_KEY": "sk_live_your_key_here"
}
}
}
}Add this server under "mcpServers" in ~/.cursor/mcp.json:
{
"mcpServers": {
"hevy-mcp": {
"command": "npx",
"args": ["-y", "hevy-mcp"],
"env": {
"HEVY_API_KEY": "your-api-key-here"
}
}
}
}For a generic setup flow across MCP clients, use add-mcp:
npx add-mcp hevy-mcp --env "HEVY_API_KEY=secret"This bootstraps the hevy-mcp entry in your client config without manual JSON edits.
oxlint/oxfmt) for near-instant linting and formatting.Supply your Hevy API key via:
HEVY_API_KEY (in .env or system environment).--hevy-api-key=your_key (after -- in npm scripts).# Example .env
HEVY_API_KEY=your_hevy_api_key_herehevy-mcp includes Sentry monitoring to observe errors and usage in production. It initializes @sentry/node with tracing enabled and PII collection disabled by default. Recent observability changes also add:
HEVY_API_KEY, so the raw key is never sent to Sentry<details> <summary><strong>⚠️ Deprecation Notices (HTTP/SSE & Docker)</strong></summary>
As of version 1.18.0, hevy-mcp only supports stdio transport. HTTP/SSE transport has been completely removed to simplify the codebase and focus on the native MCP experience.
Docker-based workflows are retired. The provided Dockerfile now exits with a message pointing to the stdio-native experience. Legacy GHCR images are no longer updated.
</details>
| Category | Tools |
|---|---|
| Workouts | get-workouts, get-workout, create-workout, update-workout, get-workout-count, get-workout-events |
| Routines | get-routines, get-routine, create-routine, update-routine |
| Templates | get-exercise-templates, get-exercise-template, search-exercise-templates, create-exercise-template, get-exercise-history |
| Folders | get-routine-folders, get-routine-folder, create-routine-folder |
| Body Measurements | get-body-measurements, get-body-measurement, create-body-measurement, update-body-measurement |
| User | get-user-info |
| Webhooks | get-webhook-subscription, create-webhook-subscription, delete-webhook-subscription |
npm run buildnpm run check (uses oxlint/oxfmt)npx vitest run --exclude tests/integration/**npm test (requires HEVY_API_KEY)For a detailed senior engineer guide, please refer to AGENTS.md.
The API client is automatically generated from the OpenAPI spec using Kubb:
npm run build:clientContributions are welcome! Please open an issue or PR for any major changes.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.