Tzilla Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Tzilla Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A local MCP server that lets an MCP client (Claude Desktop, Claude Code, Cursor, …) act as a Trainzilla coach. It wraps the existing GraphQL API at api.tzilla.live — no direct DB access — so all auth and business rules stay enforced by the backend.
Status: Local MVP — read tools, offline calculators, and confirm-gated write tools, plus a resource + a prompt. Not deployed anywhere. Runs entirely on your machine against your own coach login.
Read (live data):
whoami, list_clients, get_client_profilelist_client_habits, get_habit_compliance, recent_habit_activity, master_habitslist_workout_plans, list_diet_planslist_checkins, list_sessions, list_subscriptions, billing_summaryCalculators (offline, no network):
calc_tdee — BMR / TDEE / recommended caloriescalc_macros — macro split by strategy (Standard 40/30/30, Pro g/kg, Keto)calc_1rm — 1-rep-max (Epley) + %1RM weight suggestionsWrite (confirm-gated): every write tool returns a preview unless called with confirm: true, so nothing changes by accident:
create_habit, create_master_habit, assign_master_habitcreate_checkin (with questions), schedule_sessioncreate_workout_plan, create_diet_planStill not exposed: deletes, payment execution/refunds, messaging, permission changes — by design.
Resource: tzilla://client/{clientId}/profile — a client's profile as JSON.
Prompt: weekly_client_review — pulls profile/habits/compliance/sessions and writes a read-only weekly review.
npm install
npm run buildCreate .env (see .env.example) with a coach's tokens. Easiest source — log in to the coach web app, then in the browser console:
localStorage.getItem("token") // -> TZ_ACCESS_TOKEN
localStorage.getItem("refreshToken") // -> TZ_REFRESH_TOKENThe server auto-refreshes the access token via refreshAccessToken when it expires.
Local (stdio) — for Claude Desktop etc.:
npm run devnpm startnode scripts/smoke.mjsRemote (Streamable HTTP) — localhost only, multi-coach:
npm run http · Built: npm run start:httphttp://127.0.0.1:8787/mcp (set MCP_HTTP_PORT / MCP_HTTP_HOST).node scripts/smoke-http.mjsTZ_ACCESS_TOKEN (+ TZ_REFRESH_TOKEN) from env; auto-refreshes.TZ_API_URL wins when set.TZ_ENVIRONMENT=staging uses https://qa-be2.tzilla.live/graphql.https://api.tzilla.live/graphql.(Authorization: Bearer tz_... or x-api-key). The server never stores tokens; it forwards the caller's key to the GraphQL API, so the backend enforces scope (multi-coach safe). API keys are minted by the backend feature below.
tzilla-be, local — not deployed yet)createApiKey(name) → returns the plaintext tz_… key once + infoapiKeys (list, no secret) · revokeApiKey(id)tz_ keys (header x-api-key or Bearer), resolves theowning coach, and stamps lastUsedAt. Only a SHA-256 hash is stored.
Add to claude_desktop_config.json (Settings → Developer → Edit Config):
{
"mcpServers": {
"tzilla-coach": {
"command": "node",
"args": ["C:/New folder/tzilla-mcp/dist/index.js"],
"env": {
"TZ_API_URL": "https://api.tzilla.live/graphql",
"TZ_ACCESS_TOKEN": "<paste>",
"TZ_REFRESH_TOKEN": "<paste>"
}
}
}
}Restart Claude Desktop, then try: "Use tzilla-coach: who am I, and list my clients."
tzilla-be, local — needs PR + deploy)src/
config.ts # env + tiny .env loader
client.ts # GraphQL client: bearer auth + refresh-on-401 + role header
calc.ts # offline coach math (ported from HealthMath/WorkoutMath)
index.ts # MCP server + tool definitions (stdio)
scripts/
smoke.mjs # spawns the server and lists tools (handshake check)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.