- Reliability 8/20
- The manifest and README present a coherent design (stdio/HTTP MCP server, registry-backed package download, SQLite/FTS5 local query), but no source code, CI workflows, or committed tests were supplied to verify startup, handshake, or tool behavior. README claims were treated as untrusted evidence, and the full tool list is not specified. Deductions for lack of execution evidence and thin error-path documentation yield 8.
- Security and permissions 10/20
- No red-line issue is evident from the supplied material: credentials are stored with 0600 permissions and domain-scoped matching, and doc queries are local. However, first-use auto-downloads registry packages without documented checksum/signature verification or explicit confirmation, least-privilege scoping of the MCP session is not demonstrated, and no encryption-at-rest is mentioned. Main risks are visible but confirmation and boundary controls are incomplete, so 10.
- Maintenance 9/20
- The repository is not archived, has an Apache-2.0 license, a released npm package (0.2.3), and 0 open issues. There is no commit history, release cadence, dependency-update evidence, or security-response channel, so maintenance governance is under-evidenced. Stars are discovery signals only and were not scored. Score 9.
- Documentation 15/20
- The README is layered and strong: quick-start configs for many clients, full CLI reference, auth storage details, Docker, architecture diagram, FAQ, and registry contribution guide. It lacks a dedicated MCP tool parameter/reference section and a troubleshooting/limitations section, so it is not a perfect 20. Score 15.
- Setup experience 14/20
- Setup is straightforward: a single global npm install plus an MCP client config entry, with copy-paste examples for major clients and a Docker/HTTP alternative. The README does not state Node/npm version prerequisites, and there is no verifiable CI or committed-test evidence, so per static calibration it is capped at 15; I score 14.