- Reliability 8/20
- Evidence: The manifest claims 472 tools across 57 domains; the README describes a TCP 9878 Remote Script, UDP 9880/OSC 9881 M4L bridge, a file-based listening engine, and many version-specific fixes (event-loop offloading, stalled-stream detection, capture-pipeline timeout fixes). These narrative changelogs suggest active reliability engineering, but the manifest is the only machine-readable metadata; no repository files were supplied, so CI runs, committed tests, or actual tool-to-implementation consistency cannot be verified. Deductions: no verifiable evidence of committed tests or CI workflows; the target environment (Ableton 12, Python 3.12, Node 18+, OSC/M4L device) is complex with high failure potential; the static-review constraint caps the score at 12.
- Security and permissions 8/20
- Evidence: The v1.28.0 changelog details authentication for OSC 9881 — shared secret written to a 0600 file, rotated per startup, unauthenticated commands dropped — and a required re-freeze of the .amxd device. The README also discloses side effects beyond Live's undo stack: Splice downloads, memory/ledger writes, installer actions, atlas scans, filesystem writes. These are explicit data-flow disclosures, and downloads have a credit floor (CREDIT_HARD_FLOOR=5). Deductions: implementation is unverified from description alone; the TCP/OSC network surface can issue remote commands into a DAW with broad side effects; the license is BSL-1.1 (conflicting with the manifest's NOASSERTION, a governance inconsistency) and no security policy content was provided. No red line is triggered.
- Maintenance 9/20
- Evidence: The README shows frequent semver releases (1.27.x → 1.28.0) with substantial changelog entries, fixes from prior audits, and CI badges; 0 open issues are reported. Deductions: commit activity, release cadence, and CI status cannot be verified from the supplied materials; the license inconsistency (NOASSERTION vs BSL-1.1) and no verifiable security-response channel; v1.28.0 is very recent with no long-term track record established.
- Documentation 12/20
- Evidence: Documentation is extensive — architecture diagram, eight-layer description, tool-catalog reference, install instructions with JSON config snippets, CLI reference, compatibility table, version tiers, links to manuals/guides, and limitations (warnings about active development and pinning versions). Deductions: credentials/ports, tool parameters, and troubleshooting guides are only mentioned or linked, not included; the 472-tool count is claimed but only a curated list is shown; cost/limits are disclosed only for the Splice portion; link targets cannot be verified as real.
- Setup experience 9/20
- Evidence: Multiple paths are provided: MCPB one-click install, `npx livepilot --setup` wizard, manual Remote Script installation, and client config JSON examples for Claude Desktop/Code, Cursor, and VS Code. Prerequisites (Python 3.12+, Node 18+) are detected and clearly listed. Deductions: static review cannot verify the installers actually work; Ableton 12 plus optional M4L device/Splice app are required, so the out-of-box experience depends on an external DAW and external services; no output from the claimed verification commands (`--status`, `--doctor`) and no saved test/CI artifacts.