whoop-mcp — security grade SAFE, quality 81/100

Security audit verdict: SAFE · quality 81/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by shashankswe2020-ux · MCP Server · ★ 152

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is whoop-mcp safe to install? View the security audit →

About whoop-mcp

whoop-ai-mcp An MCP (Model Context Protocol) server that connects AI assistants like Claude to your WHOOP health and fitness data. Ask questions about your recovery, sleep, workouts, and more — all through natural conversation. 📦 Published on the MCP Registry as — discoverable by any MCP-compatible client. Features 🏋️ 6 health data tools — recovery, sleep, workouts, cycles, body measurements, and profile 🔐 Secure OAuth2 — browser-based authentication with automatic token refresh 🔄 Resilient — automatic retry on rate limits, token refresh on expiry, clear error messages 💾 Secure token storage — tokens stored at with permissions

agentskillsfitness-trackermcp-servernpm-packagewhoop-api

Quick Facts

Stars152
Forks54
LanguageTypeScript
CategoryMCP Server
LicenseMIT
Quality Score80.5832709858896/100
Open Issues32
Last Updated2026-09-10
Created2026-04-10
Platformsmcp, node
Est. Tokens~17k

Compatible Skills

These tools work well together with whoop-mcp for enhanced workflows:

  • cashclaw — semantic(0.19)+complementary+rare_topics+similar_pop+shared_platform (51%)
  • yuque-mcp-server — semantic(0.39)+same_lang+similar_pop+shared_platform (49%)
  • mcp-server-infranodus — semantic(0.29)+same_lang+similar_pop+shared_platform (45%)

whoop-mcp alternative? Top 6 similar tools

Looking for a whoop-mcp alternative? If you're comparing whoop-mcp with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • unbrowse by unbrowse-ai · ⭐ 757

    Unbrowse — api native browser Skill/CLI/MCP/SDK for any agent. Auto-discovers APIs from browser traffic, gener

  • pm-skills by product-on-purpose · ⭐ 662

    68 plug-and-play, best-practice product management skills for AI agents: 30 Triple Diamond phase + 11 foundati

  • open-harness by MaxGfeller · ⭐ 594

    A code-first, composable SDK to build powerful AI agents

  • ComfyUI_Skills_OpenClaw by HuangYuChuh · ⭐ 395

    Agent-friendly ComfyUI workflow skills for OpenClaw, Hermes Agent, Codex, and Claude Code; complementary to Co

  • cashclaw by ertugrulakben · ⭐ 295

    The Agent Economy Layer — agents earn, agents spend, Guard protects. 13 skills, runtime cost cap, recursive ki

  • claude-code-karma by JayantDevkar · ⭐ 247

    Dashboard for monitoring claude code sessions.

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular TypeScript Agent Tools

Frequently Asked Questions

What is whoop-mcp?

whoop-mcp is MCP server to connect to whoop API. It is categorized as a MCP Server with 152 GitHub stars.

What programming language is whoop-mcp written in?

whoop-mcp is primarily written in TypeScript. It covers topics such as agentskills, fitness-tracker, mcp-server.

How do I install or use whoop-mcp?

You can find installation instructions and usage details in the whoop-mcp GitHub repository at github.com/shashankswe2020-ux/whoop-mcp. The project has 152 stars and 54 forks, indicating an active community.

What license does whoop-mcp use?

whoop-mcp is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to whoop-mcp?

The top alternatives to whoop-mcp on Agent Skills Hub include unbrowse, pm-skills, open-harness. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools