- Reliability 8/20
- Evidence: README lists 12 tools with 4 always-on read-only tools and 8 write tools in Edit Mode, and mentions revision token mechanism. GitHub Actions badge implies CI, but no config or test files are visible in this static review. Since tests are not executed and tool behavior is not verified against description, reliability score is capped below 12. Repository structure is not disclosed, so error handling and dependency control cannot be verified. Deduction: lack of verifiable execution evidence such as CI workflows and committed tests.
- Security and permissions 10/20
- Evidence: Server is read-only by default, Edit Mode is opt-in, reads local SQLite directly, no network calls, no telemetry, and writes through Bear's URL handler. Security and data boundaries are clear. No credentials or malicious indicators found. Deduction: no confirmation mechanism for potentially destructive actions; tag deletion tool exists but does not delete notes. No red lines detected, and least privilege is followed by default, hence high score.
- Maintenance 8/20
- Evidence: Repository has Apache-2.0 license, recent commits (based on stars and active CI), and releases. No specific security response channel or contribution guidelines found. Deduction: commit frequency and dependency updates not verified; clear ownership and license management details not visible.
- Documentation 9/20
- Evidence: README provides installation instructions, tool list, Edit Mode configuration, debug logging, FAQ, and examples. Documentation is considered comprehensive. Deduction: lacks detailed reference on tool parameters and limits; no in-depth troubleshooting guide.
- Setup experience 9/20
- Evidence: Two clear installation paths are provided: Claude Desktop extension (.mcpb) and standalone npm package, with config examples. macOS only, which is a limitation of Bear. Deduction: installation steps not verified due to no execution; requires Node.js 24.13.0+ and Bear app, which may limit accessibility.