- Reliability 8/20
- Evidence: The repository contains substantial TypeScript source code and standard Node.js project structure (package.json, tsconfig), indicating buildability. README explicitly states startup commands (npm run build, node dist/index.js) and has src/server and src/tools directories implying MCP server implementation. However, no CI workflow or test files were directly observed, declared tool functionality is unverified by execution, error handling and dependency specifics are opaque, limiting the score.
- Security and permissions 8/20
- Evidence: The repo declares a source-available license and lists 'security-scanner' topic, hinting at security features. No overt signs of malware, credential theft, or exfiltration were found. However, permission model, data boundaries, external network behavior, and confirmation mechanisms for dangerous operations are not clear from static review, and least-privilege principle cannot be confirmed. Thus a moderate score.
- Maintenance 14/20
- Evidence: The repository shows recent release v12.6.0 and a long version history, indicating continuous maintenance. There is a clear license and sponsor mechanism, showing ownership. However, open issues count is 0 which may be due to disabled issues or lack of public discussion, and dependency update path and security response channel are not explicitly documented, deducting points.
- Documentation 16/20
- Evidence: README is highly detailed covering installation, quick start, architecture, and links to documentation, with a user guide and auto-generated reference docs. Documentation quality is high, providing layered docs (guide, reference, troubleshooting). However, some parts like license terms, tool-specific parameters, and cost details require external docs not fully embedded in README, so not full marks.
- Setup experience 12/20
- Evidence: Clear installation scripts for Windows and Linux/macOS are provided, along with step-by-step CLI commands, indicating a clear install path. However, no specific configuration examples for mainstream MCP clients (e.g., Claude Desktop, Cursor) are given, and requires Node.js 20+ and additional components, making setup non-trivial. Static review lacks execution evidence but install scripts provide consistency clues, so setup score capped below 15.