Garmin Workouts Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Garmin Workouts Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
garmin-workouts-mcp is a standalone MCP server for Garmin Connect workouts.
It is intended as a focused extension for workflows that need a bit more structure around Garmin workout payloads, especially strength training.
This project is packaged as a stdio MCP server and can be published as an OCI image for MCP registries and Glama deployment. It is not a standalone public HTTP MCP endpoint.
<a href="https://glama.ai/mcp/servers/pranciskus/garmin-workouts-mcp"> <img width="380" height="200" src="https://glama.ai/mcp/servers/pranciskus/garmin-workouts-mcp/badge" alt="Garmin Workouts MCP server" /> </a>
reps end conditions.preview_workout_payload so payloads can be inspected before upload.validate_workout for early schema and mapping errors.resolve_supported_strength_exercise for quick mapping checks.get_workout_input_schema for machine-readable client integration.walking as a supported sport type, which is also reflected in the prompt/schema.Garmin-backed tools authenticate lazily when they are called:
GARMIN_EMAIL and GARMIN_PASSWORDThe server can start without credentials. Tools that do not talk to Garmin, such as payload preview and schema inspection, still work without secrets.
The upload and preview tools accept a JSON object shaped like this:
{
"name": "Upper Day",
"type": "strength",
"steps": [
{
"stepType": "warmup",
"endConditionType": "lap.button",
"stepDescription": "General warm-up"
},
{
"stepType": "interval",
"exercise": "incline db press",
"endConditionType": "reps",
"stepReps": 8,
"stepDescription": "8-10 reps"
},
{
"stepType": "rest",
"endConditionType": "time",
"stepDuration": 120
}
]
}For strength exercises, either pass a friendly alias:
{ "exercise": "t bar row" }or explicit Garmin enums:
{
"exercise": {
"category": "ROW",
"exerciseName": "T_BAR_ROW"
}
}You can also inspect the accepted structure programmatically through get_workout_input_schema, or resolve likely Garmin strength mappings with resolve_supported_strength_exercise.
Run tests in Docker Compose:
docker compose run --rm testsBuild the runtime image:
docker build -t garmin-workouts-mcp:local .Smoke test the stdio server startup without Garmin credentials:
python - <<'PY'
import subprocess
proc = subprocess.Popen(
["bash", "-lc", "tail -f /dev/null | docker run --rm -i garmin-workouts-mcp:local"]
)
try:
proc.wait(timeout=5)
print(f"container exited early with code {proc.returncode}")
finally:
if proc.poll() is None:
proc.terminate()
proc.wait()
print("container stayed up for 5 seconds")
PYThe intended OCI image location is:
ghcr.io/pranciskus/garmin-workouts-mcpRegistry metadata lives in server.json. The OCI image carries the required label:
io.modelcontextprotocol.server.name=io.github.pranciskus/garmin-workouts-mcpGlama ownership metadata lives in glama.json. It declares the GitHub maintainer account that can claim and manage the Glama listing.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.