audit
Audit package dependencies for risks
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Package name on hex.pm | |
| version | No | Release version (defaults to latest) |
Audit package dependencies for risks
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Package name on hex.pm | |
| version | No | Release version (defaults to latest) |
Changes observed during successful MCP inspections.
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full disclosure burden, and it says almost nothing: it never clarifies whether this is read-only, whether it contacts the registry/network, what 'risks' means (vulnerabilities, outdated deps, licenses), or what happens on failure. For a tool with zero annotation coverage and no output schema, this is thin.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single six-word sentence with zero padding and the key scope front-loaded. It is efficient, though the brevity shades toward under-specification given the crowded sibling set.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Parameters are fully covered by the schema and no output schema exists, so the description needn't explain returns. What it still leaves unresolved is the disambiguation from 'audit_mix_deps'/'dependencies' and the meaning of 'risks', which an agent needs in order to choose correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so both parameters ('name' and 'version' with its latest-default behavior) are already documented in the schema. The description adds no extra meaning beyond it, which is the expected baseline when the schema does the work.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Audit package dependencies') plus an outcome ('for risks'), which is clearer than a bare name restatement. However, it does nothing to separate itself from the closely overlapping siblings 'audit_mix_deps' and 'dependencies', so an agent cannot tell which of the near-identical audit tools to pick.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no when-to-use guidance, no conditions, and no mention of alternatives. With sibling tools named 'audit_mix_deps' and 'dependencies' sitting right next to it, the absence of any routing hint is a real gap.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Add one secure layer between your agents and this server.