- Reliability 7/20
- The codebase shows a well-structured, modular architecture and an extensive test suite (20+ test files, 86% coverage claimed). However, static review cannot verify actual runtime behavior. Though CI workflows exist, they are not detailed. The tool list claims 36 MCP endpoints, but this is not verified in source; there could be mismatches. Responses are not validated by execution, so scoring is conservative.
- Security and permissions 6/20
- The server is designed to be privacy-first, keeping data local. There are no obvious credential handling issues or external network calls, but the server does include document search (RAG) involving local file access, and potential risks from PDF parsing. No confirmation mechanisms for dangerous operations are mentioned. No red lines are evident in static review, but detailed security documentation and data flow disclosures are lacking.
- Maintenance 8/20
- The project is active with recent commits and releases (version 0.9.1), and has a clear roadmap and communication channels for discussions. MIT license and a Zenodo DOI indicate long-term stability. No security response channel is identified, and dependency updates are not evidenced.
- Documentation 7/20
- The README provides a comprehensive overview, quickstart guides, a detailed tool list, report examples, and an architecture glossary. Links to deeper docs like QUICKSTART_ENGINEER.md and INSTALL.md are present. However, detailed documentation on each tool's parameters, error handling guidance, and troubleshooting specifics are missing or not verified in static analysis.
- Setup experience 6/20
- The README includes clear installation instructions, including an automated script for Windows and manual configuration (uvx, claude_desktop_config). However, static review cannot verify if the script runs without issues. Cross-platform compatibility is mentioned, but real installation verification is not provided.