- Reliability 5/20
- The review is static and based only on the supplied README and repository metadata; no server source, manifest, tests, or CI evidence was provided. The README claims two MCP tools (analyze and ai-review) and documents MCP installation, but these paths cannot be verified. The npx example uses the package name eff-u-code-mcp while installation uses eff-u-code, creating a possible package/command inconsistency. Because there is no reproducible execution evidence and the static calibration forbids a score above 12, reliability is scored 5.
- Security and permissions 7/20
- The README shows no malicious behavior or real secret examples, and it clearly separates offline local analysis from AI review requiring an external API, which is positive. However, without the server source, we cannot confirm filesystem access boundaries, protection of API keys in config files, confirmation mechanisms for MCP tools, or whether data-sending scope is controlled. The uninstall command removes global config, MCP entries, and the npm package, but no explicit confirmation flow for dangerous operations is evident. Deductions are made for incomplete least-privilege, confirmation, and scoping disclosure; score is 7.
- Maintenance 10/20
- The repository is not archived and has an MIT license. Stars are a discovery signal and do not add points. The README provides update and uninstall commands, suggesting ongoing maintenance. However, there is no commit history, release history, dependency update policy, or security-response channel, leaving governance and versioning gaps. This matches the anchor of 'active but with governance/versioning gaps', so the score is 10.
- Documentation 11/20
- The README covers installation, CLI usage, AI configuration, config-file examples, MCP installation, and client JSON examples with a clear structure. However, specific MCP tool parameters, call limits, error handling, and troubleshooting are missing. There is no layered MCP documentation and no source-level evidence to substantiate the claims. Documentation is usable but has hidden assumptions and troubleshooting gaps, hence 11.
- Setup experience 12/20
- The README provides a straightforward path: global installation, interactive mcp-install, JSON examples for Claude and Cursor, and an npx no-global-install variant. These are good setup examples. However, because no source or runtime verification was supplied, the static calibration caps setup at 15; additionally, the package-name discrepancy between eff-u-code and eff-u-code-mcp and platform-specific details are not clarified. Therefore setup is scored 12.