- Reliability 2/20
- The README describes a Next.js visual workflow application rather than a standalone MCP server; no MCP server manifest, tool list, or handshake details are supplied, and there is no test or CI evidence. Startup, MCP handshake, and tool behavior cannot be verified, so a conservative score of 2 is given.
- Security and permissions 6/20
- Clerk authentication, user-level API keys, and a User Approval node are present, with no sign of malware or hardcoded real secrets. However, least privilege, encryption of stored keys, scoping/confirmation of MCP operations, and full data-flow disclosure are missing. Main risks are visible but incomplete; score 6.
- Maintenance 7/20
- The README shows an active development roadmap, and GitHub metadata indicates the repository is not archived with 14 open issues. There is no release history, dependency update policy, or security response channel, and the license is only claimed via a README badge while the metadata says unknown. Governance and versioning gaps justify a score of 7.
- Documentation 8/20
- Installation, authentication, environment variables, example workflows, and architecture diagrams are reasonably complete for the web application. Missing MCP server tool parameters, limits, cost, and troubleshooting details, and the README does not fully match an MCP server identity, so documentation scores 8.
- Setup experience 4/20
- Setup requires Node.js, Firecrawl, Convex, Clerk, and many environment variables, with no MCP client connection examples. An install path exists for the web app, but using it as an MCP server is complex and fragile, hence a score of 4.