Skip to main content
Glama

Package Health Check

Check package.json for vulnerabilities

check_package_json
Read-onlyIdempotent

Use this when the user asks to check their package.json, or the dependencies of a project, for known vulnerabilities: "check my package.json for known vulnerabilities". Pass the text of the package.json; only the names and versions in dependencies, devDependencies and optionalDependencies are read, nothing else in the file is used or kept, and nothing is stored. Do not ask for source code or tokens. Checks up to 150 npm dependencies at the version each names (ranges at their lowest version) and returns the vulnerable ones, most severe first, with the fixed version. Dependencies without an exact version (tags, urls, workspaces) are listed as skipped.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageJsonYesThe text of the user's package.json. Only its dependency names and versions are read.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
statusYes
checkedYesDependencies looked up
messageNo
skippedYesDependencies without an exact version, not looked up
truncatedYes
cleanCountYesLooked up with no known vulnerability
skippedCountYes
vulnerablePackagesYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.1/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Adds substantial behavior beyond the annotations: it discloses that only dependency names/versions are read and nothing else is used or stored, the 150-dependency cap and lowest-version range resolution, the severity-ordered return, and that tag/url/workspace deps are reported as skipped. This goes well past the readOnly/idempotent/destructive/openWorld hints.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the trigger, then layers in input, privacy, limits, and edge-case handling. Every clause carries real information (privacy, cap, skipped deps), though the single dense paragraph could be split for easier scanning.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite having an output schema, the description supplies the runtime constraints an agent needs anyway: privacy of input, the 150-dep cap, range-resolution rule, and skipped-dependency behavior. Nothing material for correct invocation is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the single packageJson parameter and its 'text of the user's package.json' semantics are already fully documented in the schema. The description restates that input plus parsing behavior, adding only marginal value over the schema baseline.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource: checking the dependencies in a package.json for known vulnerabilities. It is highly specific about what is scanned (dependencies, devDependencies, optionalDependencies) but never names or contrasts itself with the sibling check_package, so an agent must infer which of the two to use.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives a concrete when-to-use trigger with an example user utterance ("check my package.json for known vulnerabilities") and an explicit exclusion ("Do not ask for source code or tokens"). It lacks any direct comparison to the alternative sibling tool, so routing between check_package_json and check_package is left implicit.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources