Install it the way you would
From the published package or the pinned source, in a real Claude Code setup, not a mock. If it takes a database, a key, or a browser, it gets one. A tool that only "works" in a screenshot is not vetted.
Methodology
Every listing is health-checked automatically and, when it is vetted, run and audited by a person. No rankings are for sale, and no verdict is softened because the author is watching. Here is exactly what that means. 12 tools have been through it so far.
From the published package or the pinned source, in a real Claude Code setup, not a mock. If it takes a database, a key, or a browser, it gets one. A tool that only "works" in a screenshot is not vetted.
Every listing is booted and exercised. Then the source gets read for the things a README never tells you: how many tokens it adds per session, what files and scopes it reaches, and whether anything leaves your machine.
The audit hunts for the specific catch: a write path that ignores read-only, a default that is not the safe one, a query that phones home. If there is a catch, it goes at the top of the verdict, not the footnotes.
A signed, dated take you can disagree with. Passing tools get their caveats named anyway; failing tools stay listed with the reason. Nothing is hidden, and nothing is softened because the author is watching.