PUBLIC READINESS BASELINE · JULY 27, 2026

Six passes. Two visible gaps.

This benchmark asks whether Indie Metrics MCP is inspectable, understandable, installable, safe by default, and reproducible. Failed checks are part of the record.

6 / 8current readiness checks passed

EIGHT CHECKS

Evidence before promotion.

  1. PASS
    01

    Public source is reachable

    The TypeScript repository is publicly inspectable on GitHub.

    Inspect source ↗
  2. PASS
    02

    Open-source license is present

    The repository includes an MIT license.

    Inspect source ↗
  3. PASS
    03

    Seven tools are documented

    The README names tools for revenue, customers, products, subscriptions, transactions, refunds, and forecasts.

    Inspect source ↗
  4. PASS
    04

    Independent discovery exists

    PulseMCP lists the server and PolicyLayer publishes an independent tool analysis. Listings are not endorsements.

    Inspect source ↗
  5. FAIL
    05

    npm package is available

    The package name indie-metrics-mcp returned registry HTTP 404 when checked on July 27, 2026.

    Inspect source ↗
  6. FAIL
    06

    Least-privilege key guidance is complete

    The current README shows a broad secret-key example instead of leading with a restricted Stripe key and exact permissions.

    Inspect source ↗
  7. PASS
    07

    Calculations are reproducible

    The public synthetic fixture produces expected MRR, ARR, collection, refund, churn, and risk results without a real account.

    Inspect source ↗
  8. PASS
    08

    Public remote MCP endpoint exists

    A public Streamable HTTP endpoint exposes ten tested read-only tools: seven founder-metric tools over the documented synthetic fixture, public search and fetch, and scenario comparison.

    Inspect source ↗

PATH TO 8 / 8

Turn every failure into evidence.

The score only changes when the public proof changes. These are the exact deliverables needed to close the two remaining gaps.

  1. 01

    Publish an installable package

    Current gap
    The registry record returns HTTP 404.
    Required work
    Choose and verify package ownership, publish a version with npm provenance, and make the README installation command match the released package.
    Pass evidence
    The public registry returns package metadata, a version can be installed in a clean environment, and the package exposes the documented server entry point.
  2. 02

    Document exact restricted-key permissions

    Current gap
    The README currently leads with a broad secret-key-shaped example.
    Required work
    Lead with a restricted Stripe key, list every required read permission, explain rotation and revocation, and warn users never to paste keys into chats or public forms.
    Pass evidence
    A new user can configure only the permissions required by the seven read-only tools without guessing.

METHOD

REPRODUCIBLE RECORD

Download the result, including the failures.

A pass means the linked public evidence satisfied the stated check on the verification date. It does not certify security, correctness, adoption, profitability, or production readiness.