
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
@neiltron/apple-health-mcp
Advanced tools
Local-first Apple Health MCP server. Lets AI assistants answer questions about your sleep, workouts, activity and heart data from a local export.
Query Apple Health data from an MCP client using SQL and DuckDB. The server runs locally, reads CSV exports on demand, and provides tools for schema discovery, analytical queries, and health summaries.
The native Apple Health export.xml format is not currently supported.
For Claude Desktop, add the following to
~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"apple-health": {
"command": "npx",
"args": ["-y", "@neiltron/apple-health-mcp"],
"env": {
"HEALTH_DATA_DIR": "/path/to/your/unzipped/health-export"
}
}
}
}
Restart the client after changing its configuration. Other MCP clients can use
the same command, arguments, environment, and stdio transport.
| Variable | Required | Default | Purpose |
|---|---|---|---|
HEALTH_DATA_DIR | Yes | — | Directory containing the exported CSV files |
MAX_MEMORY_MB | No | 2048 | DuckDB memory limit in megabytes |
CACHE_SIZE | No | 100 | Maximum number of cached query results |
HEALTH_DATA_DIR to the resulting directory.The server reads the files in place. It does not upload the export or make network requests, although query results returned to your MCP client may be sent to that client's configured model provider.
| Tool | Purpose |
|---|---|
health_schema | Discover table names, columns, units, and sample rows |
health_query | Run one DuckDB SELECT-family analytical statement with JSON, CSV, or summary output |
health_report | Generate a weekly, monthly, or custom health summary |
Start with health_schema; table names depend on the files in your export.
See Querying Apple Health data
for the data model and working examples.
health_query accepts one DuckDB analytical statement. See
Query safeguards
for supported statements and restricted operations.
The server limits DuckDB file access to HEALTH_DATA_DIR. It also disables
network access and temporary disk storage, and it locks the database settings.
The data directory stays readable and writable so the importer can read CSV
files.
These controls reduce accidental side effects from generated SQL. They do not
isolate the process. Run the server through a local stdio MCP client. Do not
expose it to an untrusted network client. Use process or OS isolation if the
server must accept untrusted SQL.
The first request that needs a table loads that table's full CSV history. There is no date window, so a query can reach as far back as the export goes.
Because every tool can reach the whole configured history, only start this server from an MCP client you trust with that data.
Loaded tables are held in memory, and DuckDB is given the MAX_MEMORY_MB limit
described above. Roughly 1 GiB covers a two-year multi-table export, so the
2048MB default leaves headroom; raise MAX_MEMORY_MB for a larger export. The
server never spills health rows to a temporary directory on disk, so an export
that does not fit in the limit fails with an explicit error instead.
Other current limitations:
sourceName where appropriate.git clone https://github.com/neiltron/apple-health-mcp.git
cd apple-health-mcp
bun install
npm test
npm run typecheck
npm run build
See Architecture for the code layout, data lifecycle, and implementation constraints. See Release procedure for publishing and recovery steps.
MIT
FAQs
Local-first Apple Health MCP server. Lets AI assistants answer questions about your sleep, workouts, activity and heart data from a local export.
The npm package @neiltron/apple-health-mcp receives a total of 60 weekly downloads. As such, @neiltron/apple-health-mcp popularity was classified as not popular.
We found that @neiltron/apple-health-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.