Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Beyond annotations (readOnlyHint, etc.), discloses fan-out to deps.dev and bundlephobia, timing concerns (5-30s), and graceful partial failure with sources_failed field.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Well-structured with purpose first, then usage, then behavior. Dense but every sentence adds value; could be slightly more compact but remains clear.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given no output schema, fully describes return values (summary block with fields, per-advisory detail, links, alternatives) and partial failure handling.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, and description adds context for package (scoped packages accepted) and version (defaults to latest). Provides examples of version format.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Clearly states it is a composite check for evaluating npm packages, addressing questions of safety, popularity, and size. Stands out from siblings by being a multi-source aggregation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly specifies when to use (e.g., 'is X safe / popular / small') and limits to npm ecosystem, directing other ecosystems to deps.dev directly.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.8/5.0
Disambiguation2/5

Several clusters of tools are hard to tell apart: ask_pipeworx, ask_pipeworx_beta, ask_pipeworx_grounded, and deep_research all serve overlapping query paths, and the five polymarket_* tools plus bet_research cover heavily overlapping prediction-market analysis. Some pairs are nearly identical in purpose, like ai_visibility_check vs scan_competitor_ai_presence, and the descriptions must be read closely to avoid misselection.

Naming Consistency2/5

All names are snake_case, but the naming style is highly inconsistent across the set: some use verb_noun (ask_pipeworx, generate_llms_txt, resolve_entity), some are noun phrases (entity_profile, pipeworx_feedback, recent_alerts), and some use a vendor prefix without a clear verb (polymarket_edges, polymarket_edge_tracker). The pattern shifts between domain-specific prefixes (polymarket_*, pipeworx_*) and generic verbs with no predictable rule.

Tool Count2/5

32 tools is too many for a cohesive server, especially when the surface sprawls across unrelated domains: data querying, prediction markets, memory, subscriptions, npm scanning, AI visibility checks, and llms.txt generation. Many tools could be consolidated (the ask_pipeworx family, the polymarket family, the entity-comparison family), which would make the count feel more justified.

Completeness4/5

Within its apparent purpose as a broad data-and-research assistant, the tool set is fairly complete: it covers entity resolution, lookup, grounded verification, deep research, comparisons, memory CRUD, subscription lifecycle, discovery, and feedback. Minor gaps exist, such as no direct tool to fetch a record by its pipeworx:// citation URI (search_within implies fetching happens elsewhere) and no evident update operation for stored memories beyond save/delete.