Skip to main content
Glama

Scan GitHub Repository Before Install

scan

Static supply-chain security scan of a public GitHub repo before an agent installs/runs it. Flags exfil sinks, obfuscation, credential reads, install-time curl|bash. risk=clean|suspicious|dangerous.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
repoYesPublic GitHub repo: owner/name or URL

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
okYes
repoYes
riskYes
branchYes
summaryYes
findingsYes
scannedAtYes
disclaimerYes
filesScannedYes

TDQS

A4.2/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations present, the description must reveal behavioral characteristics beyond what a machine would infer. It does provide safety-relevant behavior details: it flags specific risk signals (exfiltration sinks, obfuscation, credential reads, install-time curl|bash) and a tri-state risk verdict, giving the agent a reasonably complete behavioral picture of the scan.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is compact: three dense sentences, with semicolon-separated list of risk flags, and a clear risk-delimited output. No filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool has an output schema defining the risk result and a modest single input parameter. The description does not fully specify whether the scan executes code locally, network-access requirements, or specific permissions. However, for a public-repo static scanner with a clear output score, this is largely a complete context.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema fully documents the 'repo' parameter (owner/name or URL). The description adds only marginal context (that the repo must be public and is on GitHub), which is useful but not a transformative explanation of parameter semantics.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb 'Scan' with a clear resource ('public GitHub repository') and temporal scope ('before an agent installs/runs it'), distinguishing it as a supply-chain security scanner rather than a general code-generation or procurement tool.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It clearly situates the tool's purpose: security scanning of public repos prior to install. However, it does not explicitly state when not to use it (e.g., for PRIVATE repos or after code execution) or name alternative tools, though the static-context makes the intended trigger scenario strong enough.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.1/5.0
Disambiguation3/5

Several tools cluster around the same domain: there are multiple audit tools, multiple preflight tools, multiple receipt/settlement tools, and two wallet-policy-conformance tools. The descriptions are carefully distinguished with 'use X instead' notes, but an agent would still need to read closely to separate `agent_discoverability_audit` from `agent_surface_budget_audit` and `seller_integrity_audit` from `payment_offer_preflight`.

Naming Consistency4/5

Most names follow a readable, snake_case pattern with a domain prefix or action stem, such as `morpho_position`, `transaction_receipt`, `wallet_enrich`, and `contract_qualified_search`. The convention is not fully uniform—`read`, `extract`, `scan`, and `schemaforge` are standalone verbs or compounds, and `agent_surface_budget_audit` is a much longer construction—but the style is consistent enough to navigate.

Tool Count3/5

22 tools is at the heavy end of a data-gateway scope, especially since they spread across x402 discovery, Morpho lending, web domain audits, wallet policy, and blockchain receipts. Each tool explains its existence, but the set feels broader than one central data-gateway concern.

Completeness4/5

The tools form a coherent read-only x402/agent-commerce lifecycle: catalog search, discoverability, surface/seller integrity, payment offer preflight, settlement proof, and transaction receipt verification. There are some peripheral tools that do not directly serve x402, and no payment or execution action exists, but the read-only audit gate is intentionally complete and lacks dead ends.