- Reliability 5/20
- The server is a real TypeScript project with build and test scripts, but no CI workflow is provided, and key behaviors (MCP handshake, tool registration, API call correctness) cannot be directly verified from the repository. Tests cover only auxiliary transformation logic, not the server's core paths. Error handling is documented, but runtime depends on an external, reverse-engineered Rohlik API with limited stability and controllability. Reliability score is low.
- Security and permissions 6/20
- The server requires plaintext username and password stored in environment variables, which is common but exposes credentials. It communicates with the Rohlik API over HTTP, with no explicit mention of TLS enforcement or certificate validation. No confirmation mechanism exists for actions like adding items to cart or fetching order history, which may be performed inadvertently. Since the server only performs cart operations (no deletion or payment), the risk is moderate. No clear credential protection guidance (e.g., secret management) is provided, and the reverse-engineered API may carry implicit risks.
- Maintenance 12/20
- The repository has recent commits, 117 stars, and 4 open issues, indicating ongoing maintenance. MIT license exists, with versioning and NPM publishing workflow. However, no explicit security response channel (e.g., SECURITY.md) or dependency update policy is present. Dependency management is opaque, and the reverse-engineered API may pose maintenance challenges.
- Documentation 13/20
- README is very detailed: covers installation, configuration, tool descriptions, troubleshooting, debugging, and API validation usage. Provides examples for multiple platforms and includes a guide for newcomers and smart shopping tools. However, complete tool parameter lists are missing, and potential side effects on user accounts are not fully disclosed. Troubleshooting is comprehensive but depends on external API stability, and limitations such as cost or rate limits are not mentioned.
- Setup experience 11/20
- Installation steps are clear: requires Node.js and npm, with options for npx or local build. Provides Claude Desktop configuration examples with Windows and macOS paths. However, setting up environment variables and ensuring Node version compatibility may be extra steps. The need for real account credentials to run increases the barrier. No Docker or simplified deployment method is provided.