Skip to main content
Glama

Analyze transitive dependencies for vulnerabilities

analyze_transitive_dependencies
Read-only

Recursively resolves one or more direct/root packages' dependency graphs — e.g. the "dependencies" section of a package.json — up to maxDepth levels deep (default 2, max 3) and batch-checks every resolved package@version against OSV.dev, so vulnerabilities buried several levels down (which would never show up from checking direct dependencies alone) still surface. summary is a one-sentence, deterministic recap (packages scanned, unresolved count, vulnerable count and which roots pulled them in) — read it first. The vulnerablePaths field directly answers "which of my dependencies pulled this in" by naming the root package(s) responsible for each vulnerable transitive package; nodes has the full resolved graph (depth, parents, resolutionError) for deeper inspection. An npm alias (e.g. "totally-safe": "npm:minimist@0.0.8") is followed to its real target — actualName names the real package that vulnerability data attaches to (name stays the declared/alias key) — this is NOT silently skipped, since doing so would mean a vulnerable package hides behind whatever name a project calls it. A node with resolutionError set (unsatisfiable range, 404, or a git/file/workspace/URL specifier — those still aren't followed, only npm: aliases are) has isVulnerable: null, not false — it was never actually scanned, so "not vulnerable" would be a fabricated clean bill of health; only trust isVulnerable: true/false once a real version was resolved and checked. Scope/limits worth knowing before trusting a "clean" result: only the "dependencies" field is followed (not devDependencies/peerDependencies/optionalDependencies); each range is resolved independently per branch via semver max-satisfying against published versions — this does NOT emulate npm/yarn's actual node_modules hoisting/dedup, so read results as "which vulnerable versions are reachable in the graph," not the exact installed layout; and the whole traversal is capped at a total node budget — check truncated/truncationNote rather than assuming a large graph was scanned exhaustively. Prefer batch_query_vulnerabilities instead when you only need to check exact packages you already have a flat list for (faster, no graph walk).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
maxDepthNoHow many levels of transitive dependencies to expand beyond the given root packages (0 = only check the roots themselves). Default 2, capped at 3 to bound registry calls and stay within the request timeout.
packagesYes1-15 direct/root packages to expand from, e.g. a package.json's "dependencies". version accepts an exact version or a semver range like "^4.17.21"; omitted = latest.

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
nodesYes
rootsYes
summaryYes
maxDepthYes
truncatedYes
enrichmentNoteYes
truncationNoteYes
unresolvedCountYes
vulnerablePathsYes
totalPackagesScannedYes
totalVulnerabilitiesYes
vulnerablePackageCountYes

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changed
    • addedOutput schema / properties / nodes / items / properties / actualName
      Added value: +{
      +  "type": [
      +    "string",
      +    "null"
      +  ]
      +}
    • changedOutput schema / properties / nodes / items / properties / isVulnerable / type
      Previous value: -"boolean"New value: +[
      +  "boolean",
      +  "null"
      +]
    • changedOutput schema / properties / nodes / items / required
      Previous value: -[
      -  "name",
      -  "version",
      -  "depth",
      -  "isRoot",
      -  "rootPackages",
      -  "parents",
      -  "npmscanUrl",
      -  "resolutionError",
      -  "isVulnerable",
      -  "highestSeverity",
      -  "vulnerabilities"
      -]New value: +[
      +  "name",
      +  "actualName",
      +  "version",
      +  "depth",
      +  "isRoot",
      +  "rootPackages",
      +  "parents",
      +  "npmscanUrl",
      +  "resolutionError",
      +  "isVulnerable",
      +  "highestSeverity",
      +  "vulnerabilities"
      +]
  2. Added

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly/openWorld/non-destructive behavior, so the description had a lower bar but exceeded it substantially. It discloses npm alias following to actualName, resolutionError producing isVulnerable: null rather than false, independent semver max-satisfying resolution per branch, and truncation via truncated/truncationNote. This gives the agent a faithful model of edge-case behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is long but front-loads the core purpose and then systematically covers return fields, edge cases, limits, and alternatives. Every section earns its place given the tool's complexity, and there is no filler or redundant restatement of exact schema text.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With an output schema present, the description need not restate return structures, yet it still names key output fields like summary, vulnerablePaths, nodes, and truncated/truncationNote with enough interpretation to use them correctly. It also covers npm aliases, resolution errors, traversal limits, and when to use a sibling tool, making the description highly complete.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already covers both parameters with 100% description coverage, including maxDepth default and packages format. The description adds valuable real-world grounding by referencing package.json dependencies, depth defaults and caps, version range semantics, and alias resolution behavior, going modestly beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a specific verb-resource pair: recursively resolves dependency graphs and batch-checks resolved packages against OSV.dev. It also distinguishes itself from a flat-list alternative by explicitly mentioning transitive vulnerabilities and naming batch_query_vulnerabilities as the sibling it is not.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit routing guidance: prefer batch_query_vulnerabilities when you already have a flat list of exact packages, and use this tool when you need graph traversal across transitive dependencies. It also states scope boundaries such as only following the dependencies field and not emulating npm hoisting, which further clarifies when results are appropriate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources