Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, and destructiveHint. The description adds valuable behavioral context: partial failures degrade gracefully, bundlephobia's first measurement can take 5-30s, and sources_failed lists timeouts. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is detailed but well-structured, with a leading parenthetical summary, then use case, return block details, ecosystem scope, and failure behavior. It is dense but not overly verbose; however, it could be slightly more concise.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (composite, two services, partial failures), the description covers key aspects: what it returns (summary block, per-advisory detail, links, alternative versions), ecosystem, failure mode, and timeout. No output schema exists, so description sufficiently explains return values.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so baseline is 3. The description adds context that package accepts scoped names (e.g., '@types/node') and that version defaults to latest. This adds marginal value beyond the schema descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states it performs a composite check for adding an npm package, combining deps.dev and bundlephobia. It specifies the resource (npm package) and action (scan), and distinguishes from siblings by noting NPM ecosystem scope and mentioning alternatives for other ecosystems.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly mentions when to use: when an agent asks about safety, popularity, size, or cost of adding a package. It also notes that PyPI/Maven/Cargo/Go fall under deps.dev:version directly, providing alternatives. However, it does not explicitly state when not to use within the NPM ecosystem.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.9/5.0
Disambiguation2/5

Several tool clusters are nearly indistinguishable in purpose: ask_pipeworx, ask_pipeworx_beta, ask_pipeworx_grounded, and deep_research all route to the same underlying catalog, and the six polymarket tools heavily overlap in surfacing prediction-market edge. Even with detailed descriptions, an agent could easily misselect between bet_research and polymarket_edges or between discover_tools and suggest_questions.

Naming Consistency3/5

Most names use lowercase snake_case, but the pattern is mixed: some are verb_noun (compare_entities, resolve_entity), some are bare verbs (remember, forget, recall), and some are compound noun phrases (polymarket_edges, pipeworx_trending). ask_pipeworx also breaks the separator convention compared to ask_pipeworx_beta and ask_pipeworx_grounded.

Tool Count2/5

With 32 tools, this exceeds the 25+ threshold for 'too many' and feels like a platform bundle rather than a focused server. It spans data querying, prediction markets, memory, subscriptions, feedback, AI visibility, dependency scanning, and llms.txt generation, which is far more surface area than one coherent server should present.

Completeness4/5

For the core data-research and prediction-market domains, coverage is strong: query, grounded verification, deep research, entity resolution, comparisons, change feeds, arbitrage, fill-risk, subscriptions, and memory are all present with no major dead ends. The gaps are mostly the single-purpose oddballs (could_have_been_email_analyze, generate_llms_txt, scan_dependency) that don't connect to the rest of the surface.