Skip to main content
Glama

AlpineDataWorks Intelligence Server

Open-Source Vulnerability Density

adw.adw_418
Read-only

Returns a 0-100 software-supply-chain risk-momentum score (18 top npm/PyPI packages' OSV.dev vulnerabilities, recent 90 days z-scored vs the prior eight 90-day windows; 50 = baseline, higher = accelerating) with vulnerability_density_score, risk_level, basket_z, and recent_vulns_90d. Call when the user asks about open-source vulnerability trends, npm or PyPI supply-chain risk, or disclosure momentum, or when timing dependency upgrades, automerge policy, or a patching sprint. Updates: daily.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
daysNoOptional: return a daily HISTORY series of the last N days (up to 5 years of real archived data) instead of the current snapshot. History requires Gold tier; without it, the current snapshot is returned.

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With readOnlyHint=true, the description doesn't need to state safety, but it adds valuable context beyond annotations: the update frequency ('Updates: daily'), the scoring interpretation (50=baseline, higher=accelerating), and the Gold-tier requirement for history requests ('History requires Gold tier; without it, the current snapshot is returned'). These enrich the behavioral model without contradicting annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is information-dense, consisting of one long sentence that packs in the return value, calculation methodology, output fields, usage scenarios, and update cadence. Every clause serves a purpose and avoids fluff, though it is somewhat lengthy and could be split for readability.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The description covers the tool's core output, interpretation, typical use cases, update schedule, and the optional parameter's behavior (including the tier restriction). Despite lacking an output schema, it enumerates the returned fields, making the tool's behavior fully comprehensible for an agent.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% for the only parameter (days), and the schema description already explains its effect, range, and tier dependency. The tool description does not add further parameter semantics, but the schema carries the burden, so the baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly defines the tool's purpose: it returns a 0-100 software-supply-chain risk-momentum score based on OSV.dev vulnerabilities from top npm/PyPI packages, with specific output fields listed. This is a specific verb (Returns) and resource (risk-momentum score), and the level of detail (calculation method, baseline) makes it distinct from any sibling tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states when to call the tool: 'Call when the user asks about open-source vulnerability trends, npm or PyPI supply-chain risk, or disclosure momentum, or when timing dependency upgrades, automerge policy, or a patching sprint.' It does not explicitly state when not to use it or name alternative tools, but the triggers are clear and actionable.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

B3.3/5.0
Disambiguation1/5

With 318 tools named adw.adw_###, agents cannot tell them apart without reading full descriptions. Multiple tools cover the same domain (e.g., at least three USD strength scores: adw_055, adw_250, adw_580; four supply-chain stress scores: adw_009, adw_019, adw_020, adw_547), making misselection highly likely.

Naming Consistency3/5

The vast majority follow a consistent numeric ID pattern (adw.adw_###), but a small set breaks this with descriptive snake_case names (adw.catalog, adw.sample, adw.county_cancer, etc.). The numeric IDs are predictable but convey no semantic meaning, mixing with the few named tools and creating moderate inconsistency.

Tool Count1/5

318 tools is far beyond any reasonable scope for an intelligence server; even the largest sophisticated APIs rarely exceed 50. This extreme count suggests poor curation and will overwhelm agents with choice, making efficient tool selection impractical.

Completeness3/5

The server covers an extremely broad range of domains (crypto, macro, supply chain, healthcare, climate, county demographics), and includes discovery tools like adw.catalog and adw.sample. However, the surface is redundant and not systematically complete—many overlapping indices exist while other potentially valuable operations (e.g., raw data export, historical trend queries) are missing, leaving moderate gaps.

Resources