whichlib
Server Details
Dependency picker for coding agents: recommends, compares and scores GitHub repos with a verdict.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP · MCP 2025-11-25
- URL
- Repository
- josifb/whichlib
- GitHub Stars
- 0
- Server Listing
- whichlib
TDQS
Scored across 3 tools
The three tools target clearly distinct use cases: comparing repos you already know, recommending repos from a plain-language need, and discovering trending projects. The descriptions explicitly cross-reference each other to route the agent correctly (e.g. 'use recommend_repos to find candidates'), eliminating overlap.
All three names follow a consistent verb/gerund + '_repos' pattern (compare_repos, recommend_repos, trending_repos), giving a predictable, readable convention throughout.
Three tools is on the lean side, but for a focused library-discovery/evaluation service each tool covers a genuinely distinct workflow and earns its place. It is well-scoped rather than padded.
The surface covers the core lifecycle of finding and evaluating libraries: need-based recommendation, direct comparison of known candidates, and discovery of trending projects. A single-repo detail lookup could be a minor addition, but the main workflows have no dead ends.
Available Tools
3 toolscompare_reposCompare repositoriesARead-onlyInspect
Compare 2-10 known GitHub repositories side by side, best score first: score and tier, stars, forks, open issues, last push, license, npm/PyPI weekly downloads (only when the registry links back to the repository) and a verdict. Each result has a 0-100 score (momentum 40% (stars gained per week; without history, lifetime stars per week scaled by the npm/PyPI download trend), maintenance 25%, adoption incl. npm/PyPI weekly downloads 25%, license 10%), a tier (Strong >=75, Solid >=50, Watch >=25, Avoid <25; New for repos under 30 days old, too new to judge), a one-line verdict and the full breakdown. Use this to choose between candidates you already have (for example zod vs valibot) or to check a dependency the project already uses; use recommend_repos to find candidates. One GitHub API call per repository plus npm/PyPI lookups. A repository that does not exist is listed under notFound and the rest are still compared; the call fails only if none can be fetched, or when GitHub's rate limit is reached or the token is rejected. Hosted: 50 free tool calls per day per user; send header X-GitHub-Token with your own GitHub token for unlimited use, or run the npm package locally (npx -y whichlib).
| Name | Required | Description | Default |
|---|---|---|---|
| repos | Yes | Repository names as owner/repo, e.g. ["colinhacks/zod", "fabian-hiller/valibot"]. Not URLs or npm/PyPI package names. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes far beyond the readOnlyHint/openWorldHint annotations: it discloses the scoring formula and weights, tier thresholds, the one-API-call-per-repo cost, npm/PyPI lookups, partial-failure behavior (notFound vs total failure), rate-limit and token-rejection failure modes, and the 50-call/day hosted quota with the X-GitHub-Token escape hatch. This is unusually rich operational context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the core comparison purpose and output, and every clause carries real information (weights, tiers, failure modes, quota). It is a dense single paragraph rather than a tautological one, though the sheer density slightly hurts scannability.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description still explains return values (score, tier, verdict, breakdown) and the notFound container, and it covers auth, rate limits, and failure conditions. Nothing an agent needs to call this correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% and it already documents owner/repo format and the 2-10 range, so the baseline is 3. The description still adds value by emphasizing 'known' repositories (i.e. ones that must exist and can land in notFound) and repeating the 2-10 bound in context, reinforcing the constraint beyond the raw schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (compare) and resource (2-10 known GitHub repositories), plus the output shape (score, tier, stars, forks, verdict). It explicitly distinguishes itself from recommend_repos in the same sentence, so an agent can route between the two siblings without extra inference.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Names the exact scenario ('choose between candidates you already have, for example zod vs valibot') and its alternative ('use recommend_repos to find candidates'). The when-to-use vs when-not distinction is explicit and actionable.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
recommend_reposRecommend repositoriesARead-onlyInspect
Find the best open-source library for a need before adding a dependency. Give the need in plain words and get up to limit GitHub repositories ranked by fit = score x relevance to the need. Each result has a 0-100 score (momentum 40% (stars gained per week; without history, lifetime stars per week scaled by the npm/PyPI download trend), maintenance 25%, adoption incl. npm/PyPI weekly downloads 25%, license 10%), a tier (Strong >=75, Solid >=50, Watch >=25, Avoid <25; New for repos under 30 days old, too new to judge), a one-line verdict and the full breakdown. Use this when you do not yet have candidates; use compare_repos when you already have names. Makes 3 GitHub searches plus npm/PyPI lookups for the shortlist. Hosted: 50 free tool calls per day per user; send header X-GitHub-Token with your own GitHub token for unlimited use, or run the npm package locally (npx -y whichlib).
| Name | Required | Description | Default |
|---|---|---|---|
| need | Yes | The need in plain words, e.g. "python pdf parser", "react state management". Name the task, not a library. | |
| limit | No | How many repositories to return, 1-10. | |
| language | No | GitHub language name, e.g. "TypeScript", "Python", "Rust", "C++". JavaScript also matches TypeScript repositories and the reverse; Python also matches Jupyter Notebook. Omit to search all languages. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only declare readOnlyHint and openWorldHint, but the description adds substantial context beyond them: the cost profile ('makes 3 GitHub searches plus npm/PyPI lookups for the shortlist'), hosted rate limits (50 free calls/day), an auth requirement (X-GitHub-Token header for unlimited use), and a local fallback (npx -y whichlib). It also discloses the scoring model and tier thresholds so the agent can interpret output.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with purpose and routing, then cost/auth details. It is dense and runs long for a single block, but nearly every clause carries decision-relevant information (routing, cost, auth, scoring, tier interpretation), so the length is largely earned rather than padding.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description still covers the return shape (0-100 score with weighted sub-components, tier bands, one-line verdict, full breakdown) and the operational envelope (latency, rate limit, auth, local alternative). An agent has everything needed to call and interpret this tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents need, limit and language with examples and constraints. The description adds the notion that results are ranked by fit = score x relevance and that limit caps returned repos, but no syntax or format detail beyond the schema. Baseline 3 applies when the schema carries the parameter burden.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
Opens with a specific verb+resource+outcome: 'Find the best open-source library for a need before adding a dependency.' It explicitly distinguishes itself from the sibling compare_repos ('use compare_repos when you already have names'), so an agent can route without opening either schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Gives an explicit when-to-use ('when you do not yet have candidates') and the alternative with its trigger condition ('use compare_repos when you already have names'). The precondition of needing a plain-words need rather than a library name is also stated.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
trending_reposTrending repositoriesARead-onlyInspect
Discover projects: the most-starred GitHub repositories created in the last day, week or month, or with period "rising" repositories of any age that gained the most stars this week (like GitHub Trending; risingRank keeps that order). Optionally one language; each scored and returned sorted by score (starsRank keeps the stars order). Each result has a 0-100 score (momentum 40% (stars gained per week; without history, lifetime stars per week scaled by the npm/PyPI download trend), maintenance 25%, adoption incl. npm/PyPI weekly downloads 25%, license 10%), a tier (Strong >=75, Solid >=50, Watch >=25, Avoid <25; New for repos under 30 days old, too new to judge), a one-line verdict and the full breakdown. Not the right tool for picking a dependency, since new repositories have little maintenance history; use recommend_repos for that. One GitHub search (rising: one download of the daily list from raw.githubusercontent.com instead), plus one npm/PyPI lookup per repository when withDownloads is true. Hosted: 50 free tool calls per day per user; send header X-GitHub-Token with your own GitHub token for unlimited use, or run the npm package locally (npx -y whichlib).
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | How many repositories to return, 1-100. | |
| period | No | "day", "week" or "month": repos created in the last 24 hours, 7 days or 30 days. "rising": repos of any age by stars gained this week (the top 1,000 repos per language plus new ones are tracked). | week |
| language | No | GitHub language name, e.g. "TypeScript", "Python", "Rust". Matches that language only. Omit for all languages. | |
| withDownloads | No | Also look up npm/PyPI weekly downloads for each repository. Slower: one registry lookup per repository. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations only declare readOnly and openWorld, but the description goes far beyond: it discloses the exact scoring weights, tier thresholds, the underlying network calls (one GitHub search or one raw.githubusercontent download plus one npm/PyPI lookup per repo when withDownloads is true), rate limits (50 free calls/day), the auth mechanism (X-GitHub-Token header), and a local-run option. This is unusually rich behavioral context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Purpose and the sibling exclusion are front-loaded, and most sentences carry distinct information. It is dense and long, with the full scoring breakdown arguably more than an agent needs to select the tool, so it is slightly over-full rather than maximally tight.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
No output schema exists, yet the description fully characterizes the return values (0-100 score, tier labels, one-line verdict, full breakdown), plus cost, latency, auth, and rate limits. Nothing an agent needs to call it correctly is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, and the description adds real meaning: 'risingRank keeps that order' and 'sorted by score (starsRank keeps the stars order)' explain the ordering consequences of period, and it clarifies that withDownloads trades speed for registry data. The parameter coverage is strong; only minor format detail is absent from the description vs. schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource (discover the most-starred GitHub repositories created in a time window, or period='rising' repos by weekly star gain), and explicitly distinguishes itself from recommend_repos. An agent can identify what this returns and how it differs from compare_repos/recommend_repos without opening any schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly names the alternative and the condition that selects it: "Not the right tool for picking a dependency... use recommend_repos for that," and it explains what each period value is for. Both when-to-use and when-not-to-use are covered.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
3 tool updates
- First observed
compare_repos - First observed
recommend_repos - First observed
trending_repos
Related MCP Connectors
Finds real, maintained open-source repos that fit your project. MCP grounding for coding agents.
Trust-check any dependency for agents: OpenSSF Scorecard, licenses, CVEs, deps. 7 ecosystems.
GitHub project health, package dependency risk, trending repos, license & package comparison.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Related MCP Servers
- AlicenseAqualityAmaintenanceEnables AI agents to discover and evaluate GitHub repositories from natural-language feature descriptions, returning ranked adoption-grade candidates with evidence and quality signals.31MIT
- AlicenseNot gradedqualityFmaintenanceOpen source intelligence for AI agents — GitHub project-health scoring, package dependency-risk analysis, trending repositories, license checks, and side-by-side package comparison.MIT
- AlicenseAqualityAmaintenanceDependency intelligence for AI agents. CVE scanning, health checks, upgrade planning.9111 npm2Apache 2.0
- AlicenseNot gradedqualityCmaintenanceDiscover, rank, and compare GitHub repositories from any MCP-compatible AI client. Enables searching, filtering, ranking, and evaluating open-source repositories by topic, language, stars, license, activity, and relevance.MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.