- Reliability 7/20
- Evidence is limited. No tests or CI config visible, so cannot verify clean startup or that declared tools match behavior. Only three tools listed in README (tiktok_get_subtitle, tiktok_get_post_details, tiktok_search). Might work, but lack of reproducible verification keeps reliability low.
- Security and permissions 8/20
- API key passed via env var, which is good. No hardcoded secrets or malicious behavior evident. But external API (TikNeuron) and no scoping or data boundary info. No red-line issues, but security mechanisms incomplete, hence 8.
- Maintenance 7/20
- Has MIT license, but no commit/release/issue response details. Stars and open issues are zero from description, but these are discovery signals. No evidence of sustained maintenance or security response channel, so maintenance score low.
- Documentation 6/20
- README gives install and config examples, including env var for API key and client config. But lacks parameter limits, costs, troubleshooting, and limitations. No layered docs, so documentation score low.
- Setup experience 6/20
- Install steps are clear (clone, npm install, npm run build) with client config example. But requires API key and external service, and commands not verified in docs. No automated tests or validation, so setup score below 15.