Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. First observed

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond the read-only, idempotent, open-world annotations, the description discloses valuable runtime behavior: it fans out across two external services, partial failures degrade gracefully, and the first bundlephobia measurement can take 5-30s with a sources_failed field to indicate timeouts. This is more than the annotations alone provide, covering latency and partial success scenarios. It stops short of mentioning potential rate limits or authentication needs, but the additional context is strong.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is information-dense and front-loaded with the core purpose, followed by usage, return format, ecosystem scope, and caveats. It is longer than the two-sentence ideal, but every sentence contributes distinct, non-redundant value, such as the timing note and failure handling. It earns a solid 4 for structure and economy.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description fully covers return values by naming the summary block fields, per-advisory details, links, and alternative versions. It also addresses ecosystem limitations and error behavior (bundlephobia timeout, sources_failed). Combined with the existing annotations and input schema, this gives an agent complete context to select and invoke the tool correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already has 100% description coverage for both parameters, including scoped package support and defaulting behavior. The tool description does not add any new parameter meaning beyond what the schema states; it simply references the concept of checking a package and version. Given the high schema coverage, the baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific, action-oriented phrase: 'Composite "should I add this npm package to my project" check in ONE call'. It clearly states the tool checks npm packages across deps.dev and bundlephobia, and it distinguishes itself from sibling research tools by focusing on npm package viability. The returned fields are enumerated, making the tool's scope unmistakable.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit usage triggers are given: 'Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me".' It also provides an exclusion boundary: 'NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly,' directing users to an alternative for non-NPM ecosystems. This is clear when-to-use versus when-not-to-use guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.9/5.0
Disambiguation3/5

The descriptions are extraordinarily detailed and genuinely differentiate most tools, but the set contains near-clones (ask_pipeworx, ask_pipeworx_beta which is explicitly 'identical' to it, and ask_pipeworx_grounded) plus five polymarket tools whose boundaries (arbitrage vs edges vs edge_tracker vs fill_risk vs kalshi_spread) overlap enough to cause misselection. An agent navigating this surface must read full descriptions to choose correctly, which defeats quick tool selection.

Naming Consistency3/5

Most tools follow a snake_case verb_noun pattern (ask_pipeworx, compare_entities, resolve_entity), but there are clear deviations: bare single-word verbs (remember, recall, forget, subscribe, unsubscribe), prefix-family names (pipeworx_feedback, pipeworx_trending; polymarket_edges, polymarket_fill_risk), and a disjoint ArcGIS trio (layer_info, query_layer, search_datasets) that breaks the dominant convention. It is readable but not predictable across the whole set.

Tool Count2/5

34 tools is far beyond what the 'Arcgis Orovalley' purpose warrants — only 3 tools (search_datasets, layer_info, query_layer) actually relate to GIS, with 31 unrelated tools bolted on covering financial data, prediction markets, memory, subscriptions, and AI visibility. This is a sprawling mega-server where an agent must hold an enormous option set in mind; the surface appears to be several platforms fused together rather than one well-scoped toolset.

Completeness3/5

The genuine ArcGIS surface (search datasets → layer_info → query_layer) is a complete read-only workflow with no dead ends, and the Pipeworx side is impressively comprehensive (routing, grounded answers, research, entity, compare, resolve, validate, memory, subscriptions, feedback). But the tool set as a whole serves no single coherent domain — the declared purpose (ArcGIS Oro Valley data) lacks any write/editing operations, while the majority of the surface addresses unrelated concerns, so 'complete' only applies to one small slice of the 34 tools.