Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Discloses timing behavior: bundlephobia's first measurement takes 5-30s, and sources_failed will list it if timeout. Annotations already indicate readOnly, openWorld, idempotent, non-destructive; description adds practical context about failure handling without contradiction.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences: first defines composite purpose, second gives usage and scope, third describes output and failure mode. Front-loaded with most important information; no wasted words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Covers all needed context: composite nature, data sources, output fields, ecosystem scope, version default, and partial failure behavior. No output schema, but description lists all return fields (summary, advisories, links, alternatives). Complete for a tool of this complexity.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema provides full coverage (2 params, both described). Description adds: scoped packages accepted for 'package', and 'version' defaults to latest. Baseline 3, plus extra details justify 4.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Description clearly states it's a composite check for npm packages, combining deps.dev and bundlephobia data. Starts with a clear verb-resource pair: 'should I add this npm package' check. Distinguishes from sibling tools by focusing on npm ecosystem evaluation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly tells when to use ('when agent asks is X safe/popular/small' or 'what does adding lodash cost me') and when not (NPM only; other ecosystems use deps.dev directly). Also mentions graceful degradation for partial failures.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.1/5.0
Disambiguation4/5

Most tools have distinct purposes, but some overlap exists between ask_pipeworx, ask_pipeworx_grounded, deep_research, and validate_claim, which could cause confusion. However, the descriptions help clarify when to use each.

Naming Consistency3/5

Tool names use a mix of patterns (verb_noun, noun_noun, adjective_noun) but are consistently lowercase with underscores. Some names are vague like 'forever' and 'recent_alerts', but overall readable.

Tool Count3/5

32 tools is on the high side for a single server, but many are specialized and serve a broad data query platform. Some tools are meta-tools covering multiple use cases, which could reduce the need for so many.

Completeness4/5

The tool set covers a wide range of functionalities including data querying, entity resolution, comparisons, verification, memory, subscriptions, and prediction markets. Minor gaps like data export are not critical for its purpose.