Skip to main content
Glama

Verify a dependency change after local work

verify_dependency_change
Read-onlyIdempotent

CALL after changing the manifest/lockfile and running local checks. Compares the exact evaluated target with the resolved result and caller-reported proof receipts, reports missing/failed evidence and residual risk, and labels receipts as caller asserted. It never runs commands or stores diff/check output.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
diffNo
afterYes
checksYes
evaluationYesThe verification_context object exactly as evaluate_dependency_change returned it, passed back unchanged. Its signature covers every field, so edit nothing inside it. Sending the whole evaluate result instead is accepted; the receipt is read out of its verification_context.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
toolYes
agentYes
statusYes
schema_versionYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • changedInput schema / properties / after / properties / dependency_usage / description
      Previous value: -"Optional local call shapes for this dependency under native Node with default conditions. No source, paths, local names or call arguments. Coverage is always partial; transpiled/bundled code is unsupported."New value: +"Optional local call shapes for this dependency under native Node with default conditions. No source, paths, local names or call arguments. Coverage is always partial; transpiled CommonJS output is read, bundles are unsupported. instance_member names a method called on an instance of the export."
    • addedInput schema / properties / after / properties / dependency_usage / properties / uses / items / properties / instance_member
      Added value: +{
      +  "maxLength": 100,
      +  "pattern": "^[A-Za-z_$][A-Za-z0-9_$]*$",
      +  "type": "string"
      +}
  2. Changed1 schema field changed
    • addedInput schema / properties / after / properties / dependency_usage
      Added value: +{
      +  "additionalProperties": false,
      +  "description": "Optional local call shapes for this dependency under native Node with default conditions. No source, paths, local names or call arguments. Coverage is always partial; transpiled/bundled code is unsupported.",
      +  "properties": {
      +    "coverage": {
      +      "const": "partial",
      +      "type": "string"
      +    },
      +    "runtime": {
      +      "additionalProperties": false,
      +      "properties": {
      +        "arch": {
      +          "maxLength": 32,
      +          "pattern": "^[a-z0-9_]+$",
      +          "type": "string"
      +        },
      +        "node": {
      +          "maxLength": 32,
      +          "pattern": "^[0-9]+\\.[0-9]+\\.[0-9]+$",
      +          "type": "string"
      +        },
      +        "platform": {
      +          "maxLength": 32,
      +          "pattern": "^[a-z0-9_]+$",
      +          "type": "string"
      +        }
      +      },
      +      "required": [
      +        "node",
      +        "platform",
      +        "arch"
      +      ],
      +      "type": "object"
      +    },
      +    "schema_version": {
      +      "const": 1,
      +      "type": "integer"
      +    },
      +    "uses": {
      +      "items": {
      +        "additionalProperties": false,
      +        "properties": {
      +          "export_path": {
      +            "items": {
      +              "maxLength": 100,
      +              "pattern": "^[A-Za-z_$][A-Za-z0-9_$]*$",
      +              "type": "string"
      +            },
      +            "maxItems": 2,
      +            "type": "array"
      +          },
      +          "loader": {
      +            "enum": [
      +              "require",
      +              "import"
      +            ],
      +            "type": "string"
      +          }
      +        },
      +        "required": [
      +          "loader",
      +          "export_path"
      +        ],
      +        "type": "object"
      +      },
      +      "maxItems": 50,
      +      "type": "array"
      +    }
      +  },
      +  "required": [
      +    "schema_version",
      +    "runtime",
      +    "coverage",
      +    "uses"
      +  ],
      +  "type": "object"
      +}
  3. Changed1 schema field changed
    • addedInput schema / properties / evaluation / description
      Added value: +"The verification_context object exactly as evaluate_dependency_change returned it, passed back unchanged. Its signature covers every field, so edit nothing inside it. Sending the whole evaluate result instead is accepted; the receipt is read out of its verification_context."
  4. Changed1 schema field changed
    • addedInput schema / properties / evaluation / properties / baseline_project_snapshot
      Added value: +{
      +  "const": "not_supplied",
      +  "description": "Present only when the evaluation was made without a project snapshot. Part of the signed identity — pass it back verbatim.",
      +  "type": "string"
      +}
  5. Added

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already establish readOnly/idempotent/non-destructive, so the bar is lower, and the description still adds real disclosure: it refuses to run commands, does not store diff or check output, and explicitly marks receipts as caller asserted rather than verified. That trust-model statement is exactly the kind of context annotations cannot convey.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, front-loaded with the imperative call condition, then the comparison behavior, then the negative constraints. No sentence is filler or restates the tool name.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a four-parameter, deeply nested verification tool with an output schema present, the description covers when to call, what is compared, what is reported, and what the tool will not do. Return-value detail is legitimately delegated to the output schema; only fine-grained input semantics remain thin.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is only 25% across four nested parameters, so the description must carry more weight, and it does clarify the roles of the three inputs (evaluated target, resolved result, proof receipts) at a conceptual level. However, it adds no field-level or format guidance beyond what the schema and its embedded descriptions already state.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Names a specific action (verifies a dependency change by comparing the evaluated target against the resolved result and caller proof receipts) and states its outputs (missing/failed evidence, residual risk, caller-asserted labeling). This is clearly distinguishable from evaluate_dependency_change, which produces the evaluation this tool consumes.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

"CALL after changing the manifest/lockfile and running local checks" gives an explicit triggering condition that an agent can act on. It does not name the alternative tools or state when not to call it, so it stops short of full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources