- Reliability 5/20
- Only README start commands and architecture are supplied; no package manifest, CI workflow, or tests are visible. The init/tools-list handshake and actual tool behavior cannot be verified, and error handling is unknown. Per the static calibration cap, score is 5.
- Security and permissions 6/20
- The README shows DB2i_PASS stored via .env and includes DB2i_IGNORE_UNAUTHORIZED=true; YAML tools can execute arbitrary SQL, with no evidence of least privilege, confirmation of dangerous operations, or data-flow disclosure. No malware or real tokens were found, so the red line is not triggered; score is 6.
- Maintenance 7/20
- The repository is not archived, has an Apache-2.0 license, and shows open issues, but the supplied material lacks commit history, release history, dependency updates, or a security response channel. Maintenance governance evidence is thin; score is 7.
- Documentation 13/20
- The README is broad: quickstart, environment variables, YAML tool examples, Docker, Python client, deployment, and Mapepire prerequisites, plus external doc links. However, troubleshooting, limits/cost, full parameter schemas, and mainstream client config examples are missing; score is 13.
- Setup experience 11/20
- Setup steps are clear (npx/Docker, .env, healthz verification), and a Python client example is included. But it depends on an external Mapepire service, lacks mainstream client config JSON (e.g., Claude Desktop), and has no CI/test evidence; score is 11.