Skip to main content
Glama

Check security exposure for a version

check_security_exposure
Read-onlyIdempotent

Deprecated: this evidence tool is no longer refreshed and will be removed on or after 2026-12-31. For building, use discover_daystruct_capabilities and compat_check. Given a package and the version you are running, return the known vulnerabilities that affect it, worst first, each with the version that fixes it. Advisories whose affected range could not be parsed are returned under undetermined; treat undetermined as unanswered, never as safe.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYes
versionYes
ecosystemNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare read-only and idempotent, so the description adds deprecation status and data-refresh caveat, plus the undetermined handling rule. No contradiction with annotations; the added context is valuable for an agent deciding whether to rely on the tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two concise sentences: deprecation warning first, then behavior and caveat. No redundant words; front-loaded with the most important decision-relevant info.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers the core behavior, return ordering, undetermined handling, and alternatives, but leaves the 'ecosystem' parameter unexplained and gives no example or output shape. For a deprecated tool with no output schema, this is adequate but not complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 0%, so the description must explain parameters. It implicitly explains 'package' and 'version' but does not clarify the optional 'ecosystem' parameter at all. This is a notable gap given the low coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific action: given a package and version, return known vulnerabilities sorted worst-first with fixing versions. It clearly distinguishes from siblings by naming alternatives for building and indicating deprecation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states it is deprecated and will be removed, directing users to discover_daystruct_capabilities and compat_check for building. Also provides guidance on interpreting 'undetermined' advisories, which clarifies when results are not safe.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources