- Reliability 9/20
- The README describes a coherent modular architecture (main.py, runtime.py, runner.py, tools/, sanitize.py, tests/) and unusually detailed error behavior (structured telegram_premium_required results, guided unknown-contact returns, fail-fast proxy validation, AuthKeyDuplicatedError retries). However, this static review received only the README's self-description — no source code, test files, or CI workflow files to execute or inspect. The README is untrusted evidence; its CI badges and 80% coverage gate cannot be verified. Under the static calibration, missing verifiable execution evidence caps this dimension at 12 and missing evidence is a deduction; it cannot be confirmed that the declared tools match real behavior. Therefore below the 10 anchor: 9 — the happy path looks plausible but is not reproducible or diagnosable from the supplied material.
- Security and permissions 16/20
- No red-line issue found: install examples use only placeholders; the documented design includes read-only tool gating (TELEGRAM_EXPOSED_TOOLS=read-only), mandatory allowed roots for file tools with traversal/wildcard/null-byte rejection, sanitized structured JSON with MCP audience annotations, owner-only (0600) state files, HTTP defaulting to 127.0.0.1, DNS-rebinding protection, an honest PyPI name-collision warning with an install guard, and confirm-before-send for fuzzy contact matches. Credentials are env-based with explicit 'never commit .env' warnings. Yet the server inherently wields full Telegram account authority, and the README itself discloses that read-only mode is an MCP-surface restriction, not a session sandbox; none of the safeguards could be verified in actual code. Per 'unverified means deduction', 16/20.
- Maintenance 14/20
- Factual metadata shows the repo is not archived, uses Apache-2.0, names two maintainers (@chigwell, @l1v0n1), and includes a contributing guide with pre-commit hooks; README badges reference lint/format and Docker-build workflows, indicating an actively maintained project. However, this review contains no direct evidence of commit cadence, release tags, dependency updates, issue-response timeliness, or a security-response channel; the 34 open issues cannot be assessed for response quality. Deduction for missing update-path evidence: 14/20 rather than full marks.
- Documentation 17/20
- The README is layered and exceptionally thorough: prerequisites, session-string generation (QR/phone), single/multi-account config, session pooling, proxy, device identity, file-path security policy, Docker, three transports, development/testing, security notes, and a troubleshooting table. Limitations are explicitly disclosed (rich formatting requires Telegram Premium re-checked per call, PyPI name collision, stdio-vs-HTTP trade-offs, unauthenticated HTTP endpoint), with complete client configuration JSON for Claude/Cursor. Deductions: per-tool parameter reference is only claimed to live inside server tool descriptions and cannot be verified; no documentation layer beyond the README is available; claims like '80+ tools' and the coverage gate lack source evidence. Hence 17/20.
- Setup experience 14/20
- Setup is a clear multi-path flow: git clone + uv sync, run session_string_generator.py (--qr/--phone), cp .env.example and fill credentials, run main.py; ready-made stdio configuration JSON for Claude/Cursor, Docker run/compose commands, a git-installed console-script option, and mcp-remote bridging are all provided, including allowed-roots CLI examples. Static calibration caps setup at 15 without verifiable CI/test files in the evidence, and only the README describes the process; the manual session-generation step and the PyPI name-collision workaround (clone-based install only) add real friction. Score: 14/20.