Skip to main content
Glama

Vigía

Version status and vulnerabilities

version_status
Read-only

For one exact version of an npm or PyPI package: whether it exists, when it was published, whether it was deprecated/yanked, how far behind latest it is, its known vulnerabilities (OSV) and the nearest version that fixes all of them. Use before keeping, pinning or recommending a specific version, or when auditing a lockfile entry.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameYesExact package name
versionYesExact version, e.g. "4.17.1"
ecosystemYesPackage ecosystem

Schema Changelog

Changes observed during successful MCP inspections.

  1. Added

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and openWorldHint=true, so the safety profile is covered. The description goes further by disclosing the external data source (OSV) and the fact that it reports existence, deprecation, staleness and a remediation version, which tells the agent what to expect from a call. It omits any mention of rate limits or behavior for a nonexistent version, so not a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

One dense but well-structured sentence listing the returned facets, followed by one usage sentence. Front-loaded with the scope ('one exact version'), and no sentence is redundant.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

There is no output schema, so the description carries the return-value burden and does it well by enumerating each field an agent will receive, including the remediation version and the existence flag that covers the failure case. Nothing needed to call or interpret this three-parameter read tool is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so name, version and ecosystem are already documented, including the enum for ecosystem. The description reinforces that the version must be exact and that the ecosystem is npm or PyPI, but adds no syntax or format detail beyond the schema. Baseline 3 applies when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (report on one exact version of an npm/PyPI package) and enumerates the exact facets returned: existence, publish date, deprecation/yank status, staleness vs latest, OSV vulnerabilities, and nearest fixing version. This clearly separates it from sibling package_status, which by name covers the package rather than a single pinned version.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly names the triggering situations: before keeping, pinning or recommending a specific version, or when auditing a lockfile entry. It gives no exclusions or named alternatives (e.g. when to prefer package_status or check_dependencies instead), so it stops short of a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources