- Reliability 9/20
- The manifest declares an npm stdio package, version, and default local backend, while the README describes the MCP tools and API paths, so a normal startup path is plausible. However, this is a static review with no actual initialization handshake, tool-list response, committed tests, or key-path coverage evidence. Backend auto-download, IPC/HTTP fallback, and whether all 51 tools match real behavior are unverifiable, so points are deducted and the score remains at or below the static-review ceiling of 12.
- Security and permissions 11/20
- The default API URL is 127.0.0.1, the API key is marked secret, API endpoints are documented as requiring X-API-Key, and local binding, CORS, IPC, and production settings are described. These show basic boundary awareness. Points are deducted because user_id is explicitly not an authorization tenant, the remote Zenoh example listens on 0.0.0.0, and destructive, purge, restore, and reset tools have no documented confirmation, privilege separation, or misuse safeguards. Disclosure of external network access, automatic model downloads, and complete data flows is also incomplete. No evidence establishes a red-line violation.
- Maintenance 12/20
- The repository is not archived and provides an Apache-2.0 license, a named GitHub owner, version 0.2.0, and publication paths for npm, crates.io, and PyPI; the README also shows a CI badge. Points are deducted because the supplied material contains no commit history, actual CI workflow, dependency-update policy, vulnerability-response channel, or maintenance commitment. The open-issue count cannot establish response quality, so this indicates some maintenance signals but not sustained governance.
- Documentation 14/20
- The README covers installation, client configuration, authentication variables, platforms, deployment modes, tool categories, API examples, performance claims, and diagnostic commands. Its coverage is broad. Points are deducted because per-tool parameters and return schemas, error semantics, retention and privacy limits, backup/restore risks, and reviewable test evidence are missing. The claims of no API keys also need clearer qualification given remote authentication and automatic key generation.
- Setup experience 13/20
- The README provides short Claude Code and JSON client configurations using npx -y @shodh/memory-mcp, and lists Linux, macOS, Windows, Docker, and Python paths. Points are deducted because the MCP client still depends on an automatically downloaded or separately running backend, IPC versus HTTP selection is relatively complex, and remote deployment requires additional authentication and proxy configuration. No committed end-to-end installation or connection verification evidence is supplied, so the score stays below the static-review ceiling of 15.