| FMRS | 51 / 100 · D | 77 / 100 · B | 75 / 100 · B |
| Reliability | 9 / 20 | 12 / 20 | 13 / 20 |
|---|
| Security and permissions | 5 / 20 | 16 / 20 | 12 / 20 |
|---|
| Maintenance | 11 / 20 | 16 / 20 | 16 / 20 |
|---|
| Documentation | 14 / 20 | 18 / 20 | 17 / 20 |
|---|
| Setup experience | 12 / 20 | 15 / 20 | 17 / 20 |
| Best for | - Authorized security assessment, incident response and threat intelligence teams
- AI agent workflows that need multi-source intelligence correlated in a single conversation
- Analysts wanting ransomware and breach listing data without configuring API keys
- Users already running the companion security MCP servers (hackbrowser-mcp, cve-mcp, osint-mcp-server, etc.)
| - Hevy PRO users who want AI assistants to directly access their workout data
- People who prefer using MCP clients like Claude, Cursor, Codex for fitness tracking
- Anyone needing summaries and insights from their training data
| - Scenarios needing clean, structured web context fed to an AI assistant
- Users already on the Firecrawl platform who want to call its scraping capability directly via MCP
|
| Not for | - Users performing intelligence gathering on third-party targets without authorization
- Users who expect every tool to work out of the box (several require paid or requested API keys)
- Users needing Ethereum or Monero blockchain data (Bitcoin only)
- Users needing officially supported Windows operation (only macOS / Linux are tested)
| - Users without a Hevy PRO subscription (API key required)
- Users who want to use the server without an API key
- Those needing delete workflows (Hevy API does not expose delete endpoints)
| - Simple static-page scraping where you don't want to depend on a third-party API and incur call costs
- Sites that explicitly disallow automated access (robots.txt)
|
| Required permissions | - Read third-party API keys from environment variables (HIBP, IntelligenceX, OTX, AbuseIPDB, abuse.ch, Pulsedive, Hudson Rock, Vulners, Hybrid Analysis, PhishTank)
- Communicate with a local Tor daemon over the local SOCKS5 port (default 127.0.0.1:9050)
- Make outbound HTTPS requests to 16 external data sources
- Install locally and run a process over stdio via npx / Bun
| - Requires HEVY_API_KEY environment variable for Hevy API authentication
- Can create, update, and replace workouts, routines, folders, templates, and body measurements via tools
- Read operations can fetch workouts, routines, folders, templates, history, and user info
| - Requires a Firecrawl API key to call; cost and quota are governed by the Firecrawl account
- firecrawl_agent/firecrawl_interact perform automated browser interaction, which may trigger login or form-submission flows on the target site
|
| Risks and side effects | - Dark web intelligence gathering is legally and compliance sensitive — proper authorization is essential
- Tor .onion tools leak DNS if attribution is not routed through the proxy; the project mitigates this with socks5h but users should verify their proxy setup
- API keys live in plain environment variables and could leak into logs or config files
- Tor-dependent tools are unavailable without a local Tor daemon
- Free tiers have low rate limits, so bulk queries may be throttled
- Upstream sources (e.g. ransomware.live, RansomLook, PhishTank) depend on scraping frequency, so data may lag or be incomplete
- All content returned by external sources is untrusted input and should not be executed as instructions
| - API key can be misused if leaked; do not expose in URLs, logs, or screenshots
- Create operations may produce duplicates on retry; update operations replace existing records
- The server sends data to the Hevy API and may send telemetry to external services unless disabled
| - Bulk crawl/map tools can generate significant request volume against a target site — respect the site's rate limits and terms of service
- firecrawl_agent's interactive action chain is longer — define task boundaries clearly before running it to avoid accidentally triggering actions on a sensitive site
|
| Supported clients | Claude Code, Claude Desktop, Cursor, Windsurf | Claude Desktop, Cursor, Codex, Google Antigravity | Claude Desktop, VS Code, Cursor, Windsurf, Zed, Amp |
| Tools | 66 | 26 | 11 |