- Reliability 11/20
- The manifest declares both an npx/stdio local package and a remote streamable-http endpoint, and the README's tool descriptions (geocoding, routing, isochrones, offline geometry, etc.) are detailed and consistent with the manifest description with no obvious contradictions. However, this review is based only on the README and manifest as static evidence — no CI workflow files or committed test files were included to verify behavior; the `npm test`/`npm run lint` commands mentioned in CONTRIBUTING are process claims only, not verifiable execution evidence. Per the static calibration rule, reliability is capped at 12 absent such evidence, so 11 is given: the happy path is plausible from the description, but edge cases, error handling, and dependency control remain unverified in the supplied material.
- Security and permissions 14/20
- Credential handling is reasonably well disclosed: MAPBOX_ACCESS_TOKEN is marked required+secret, and the README's 'Data Usage & Privacy' section states the token stays local and is never stored/logged by the server, while listing exactly what data each tool category sends to Mapbox APIs — a decent level of data-boundary transparency. All tools are read-only geospatial queries/calculations (geocoding, routing, isochrones, offline turf.js math, etc.); no destructive, payment, or remote-execution defaults are present, so no red line is triggered. That said, gaps remain: the manifest also declares an official hosted remote endpoint (`https://mcp.mapbox.com/mcp`) whose authentication mechanism (whether it reuses the same token, and how it's transmitted) is not described in the material, leaving the trust boundary for that path unclear; additionally, `render_map_tool` renders custom HTML/GeoJSON panels via the MCP Apps protocol, and its sandboxing/permission isolation is not detailed. This does not amount to a red-line violation, but permission/confirmation disclosure is incomplete, warranting 14.
- Maintenance 16/20
- The repository is officially maintained by Mapbox, carries a clear MIT license, and the manifest version (0.14.0) is paired with a documented release process in the README (version bump, manifest sync, changelog prep, CI validation of version consistency), showing solid release governance. The README explicitly states a 'Maintenance Commitment' promising ongoing updates, bug fixes, and MCP protocol compatibility, and lists two support channels (email and GitHub Issues). The repo is not archived, and has 350 stars with only 4 open issues, which is only a secondary signal of responsiveness (not used to add points directly). Since no actual commit timeline or recent release dates were available to verify sustained activity, it falls short of a top score — 16 is given.
- Documentation 17/20
- Documentation is layered and thorough: the main README details each tool's function, parameters, and usage examples, and links out to multiple client integration guides (Claude Desktop, VS Code, Cursor, Goose, Smolagents) as well as dedicated docs for resources, elicitations, tracing, and the render_map_tool payload schema, plus an explicit data usage/privacy section. Example prompts span discovery, navigation, visualization, and offline geometry use cases, and a deprecated tool (category_list_tool) is clearly flagged with a migration path. The gap is that concrete API cost/rate-limit details are not included in the supplied material (only links to external Mapbox docs), so it falls short of a perfect score — 17 is given.
- Setup experience 13/20
- Two setup paths are offered: using the officially hosted endpoint (no local install) or running locally via `npx @mapbox/mcp-server` with the `MAPBOX_ACCESS_TOKEN` environment variable, with clear linked steps for obtaining a token. The README also links to several client-specific configuration guides. However, per the static calibration rule, setup is capped at 15 absent verifiable CI/test evidence supporting a reproducible working connection; also, the supplied README excerpt does not itself include a copy-pasteable JSON client config snippet (configuration is spread across external linked docs), adding some friction. 13 is given.