- Reliability 4/20
- The server manifest is not cached and the supplied material contains no source files, tests, or CI workflows, so the MCP init handshake, the tool list, and whether declared tools match real behavior cannot be verified. The README shows a plausible happy path (deep-image-search-mcp --index-path ... --model ...) and a Claude Desktop config snippet, but names no tools or parameters and documents no error handling. Heavy runtime dependencies (torch, FAISS, open_clip) make a clean start uncertain. Static calibration caps reliability at 12 without execution evidence; with no test/CI evidence at all, the score stays far below that.
- Security and permissions 9/20
- No red-line issues are present in the supplied material: no malware, credential theft, covert exfiltration, irreversible destructive defaults, or real tokens in install examples. The MCP server appears scoped to read-only search over a local index, which aligns with least privilege; however, the README does not document tool-level permissions, data-flow boundaries, or any confirmation flows, and the LLM captioner expects an api_key passed as a constructor argument with no env-var or MCP-specific guidance. Main risks are visible but scoping and disclosure are incomplete; anchored at 9.
- Maintenance 11/20
- The repository is not archived, has an MIT license, and the README indicates ongoing v3 development with modern pyproject/uv packaging and maintained optional extras; ownership is clearly stated (Nilesh Verma). However, the supplied material shows no release history, commit cadence, issue-response evidence, dependency-update policy, or security-response channel (e.g., SECURITY.md). Stars are treated only as a discovery signal and add no points. This matches "active but governance/versioning gaps", with a slight bump to 11.
- Documentation 12/20
- The README is layered and unusually complete for the library itself: feature list, multiple install paths, quick start, result JSON schema, vector stores, metadata backends, an embedding presets table disclosing limitations (text-search support), agentic integration, a full architecture tree, and a 10-demo table. Deductions: the MCP-server section is thin (no tool parameter reference, no limits/cost, no troubleshooting), "Read Full Documents" is only a GitHub Markdown file, and no manifest or source substantiates that the docs match real MCP behavior — hence 12.
- Setup experience 10/20
- The install path is clear: pip with the [mcp] extra (or git install), plus a Claude Desktop JSON config example with command and args. Deductions: the prerequisite of building a vector index (torch/FAISS-heavy) is implicit and burdensome; there are no steps to verify a working MCP connection, no transport (stdio/SSE) or environment variable notes, no platform compatibility caveats, and no troubleshooting. Static calibration caps setup at 15 without execution evidence; the flow looks plausible but manual and fragile, so 10.