Evaluation report
Warnings@shareai-lab/kode · mcp60d98dd· 3 months ago
Every check MetaHub ran on this artifact, grouped by area. Static checks run on the source at publish time; behavioral checks run the artifact in a sandbox and judge what it actually does.
Structural
5 passedRepository is reachable
https://github.com/shareAI-lab/Kode-CLI @ 60d98dd — ★ 5,139 · TypeScript · Apache-2.0 · last push 11 days ago
Manifest detected
kind=mcp slug=shareai-lab-kode · source=package.json
Slug is URL-safe
"shareai-lab-kode" matches /^[a-z0-9][a-z0-9-]{0,62}$/
Slug is unique within kind
No collision found for mcp/shareai-lab-kode
Version is semver
2.2.1
Documentation
4 passed1 warningTags / topics declaredwarn
No manifest tags and no GitHub repo topics
Add tags to the manifest (or GitHub topics on the repo) so the registry's search and category filters surface this artifact.
Description quality
15 words · 126 chars — "AI-powered terminal assistant that understands your codebase, edits files, runs …"
README is present and substantial
5,376 chars · 11 sections · 6 code blocks
README has usage / example sections
found: Installation · Quick Start
Homepage / docs URL declared
https://github.com/shareAI-lab/kode
Safety
3 passedDependencies: known vulnerabilities
OSV.dev clean — 0 high/critical across 20 deps
LICENSE file at repo root
LICENSE
No sensitive files in the repo
scanned for .env, credentials.json, *.pem, .ssh/, AWS / GCP configs — none found
Kind-specific
4 passed1 warningMCP: ESM packagewarn
package.json missing "type": "module"
Modern MCP servers are ESM. Add `"type": "module"` unless you have a CJS-only reason.
MCP: launch path
bin: kode, kwa, kd
MCP: @modelcontextprotocol/sdk in dependencies
pinned at "^1.29.0"
MCP: SDK version pinned
pinned at "^1.29.0"
MCP: server surface
0 tools
Maintenance
3 passedRecent activity
last push 11 days ago
Tests detected
1 test directory · 153 test files
CI configuration detected
GitHub Actions (5 workflows)
Behavioral
This artifact hasn't produced behavioral results yet: the evaluation sandbox couldn't run it (it may need credentials we don't provide, or a build our environment doesn't support). That's a limitation of our environment, not a verdict on the artifact.