- Reliability 6/20
- Only the README and repository metadata are available. The README lists 16 tools with coherent parameters, but no source, package.json, CI, or tests were provided to verify the MCP handshake or actual tool behavior. Static calibration caps reliability at 12 and execution evidence is absent, so a conservative 6 is given.
- Security and permissions 8/20
- No red-line issues such as malware, credential theft, or real tokens in install examples were found. However, execute_script allows arbitrary JavaScript, and upload_file, cookie and navigation tools carry broad capabilities without documented sandboxing, confirmation, or data-flow boundaries, so least-privilege and confirmation are incomplete; score 8.
- Maintenance 8/20
- The repository is not archived and has an MIT license, with signs of ongoing maintenance in the README. However, no commit history, releases, or dependency updates are present in the supplied material, so maintenance activity cannot be confirmed and points are deducted; score 8.
- Documentation 16/20
- The README provides client-specific install examples, full tool tables with parameter types and defaults, resource descriptions, and development/test guidance, which is strong. It lacks troubleshooting, command limits, and security boundary documentation, and there is no verifiable source-level documentation, so a small deduction is made.
- Setup experience 14/20
- One-line npx installation and configuration examples for Goose, Claude Code, Cursor/Windsurf, and others make setup clear. Static review found no CI or committed tests as execution evidence, so per calibration setup cannot exceed 15; browser/driver prerequisites also remain, hence 14.