- Reliability 7/20
- Evidence: The README and manifest list 5 tools, but no actual server source code (no src/, package.json, tests etc.) is provided for verification. The claimed anonymous and authenticated modes, RSS fallback, and caching logic cannot be verified. No CI or test evidence is present. Therefore, per static calibration, reliability cannot exceed 12; but lacking concrete proof of actual behavior, I infer the happy path may work but error handling and dependency control are unverified, so score is low. Deductions: no source code, no tests, no CI evidence.
- Security and permissions 5/20
- Evidence: Credentials are handled via env vars or local file (--auth), with promises that passwords are never written to disk and tokens are memory-only. HTTP mode binds to localhost by default with host/origin checks. However, no source code is provided to verify these claims. Anonymous mode uses RSS, no obvious risk. No red flags found. Deductions: unable to verify security implementation; lack of explicit statement about HTTPS in transit; no evidence of log redaction for secrets.
- Maintenance 6/20
- Evidence: Repo shows active releases (1.1.14) and relatively high stars, but no commit history, issue response times, or dependency update details are provided. MIT license present. Without specific evidence, maintenance activity is scored moderate-low. Deductions: no commit/release history, issue resolution times, or dependency update records.
- Documentation 8/20
- Evidence: README is very detailed, covering installation, auth, tool parameters, rate limits, troubleshooting, privacy policy, env vars, and comparisons. Examples and expected outputs (like data_source) are explained. Deductions: lack of detailed examples of actual tool output JSON structures; documentation heavily relies on GIF demos without static screenshots for verification.
- Setup experience 7/20
- Evidence: README provides multiple installation methods (npx, global, from source, Docker, .mcpb). Clear JSON config examples for Claude Desktop are given. For other clients, npx -y command is provided. Deductions: no verification that install steps work out-of-the-box in a specific client; dependencies on node version and network; no example config file or step-by-step verification screenshots.