Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. Added

TDQS

A4.7/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses significant behavior beyond annotations: it fans out across two external services, returns a specific summary block with field names, includes per-advisory details and alternative versions, and explains partial-failure behavior with a concrete timing constraint ('bundlephobia's first measurement can take 5-30s; sources_failed will list it if it times out'). This exceeds the safety hints provided by annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but every sentence earns its place: purpose, usage context, return format, ecosystem scope, and failure-handling are each covered in separate, well-structured sentences. It front-loads the core purpose and avoids fluff. Five sentences is appropriate for a composite tool of this complexity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description must convey return values, and it does: it lists the summary fields, per-advisory detail, links, and alternative versions. It also covers limitations (NPM-only), timing, and graceful degradation, making it complete for an agent to understand what to expect and how to handle edge cases.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already covers both parameters with clear descriptions (package name, version with default behavior), and schema description coverage is 100%. The description adds context around what the tool returns but does not materially enrich the meaning of the parameters beyond what the schema already provides. Baseline of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific, concrete purpose: 'Composite "should I add this npm package to my project" check in ONE call'. It clearly identifies the resource (npm package) and the action (scan/evaluate), and immediately differentiates itself from siblings by naming the composite data sources (deps.dev, bundlephobia). It also explicitly scopes to 'NPM ecosystem only in v1', making it distinct from broader tools like deep_research.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives explicit usage triggers: 'Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me"'. It also provides a clear exclusion/alternative for non-npm ecosystems ('PyPI / Maven / Cargo / Go fall under deps.dev:version directly'), telling the agent when NOT to use this tool and what to use instead.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.6/5.0
Disambiguation2/5

Multiple tool families heavily overlap: ask_pipeworx, ask_pipeworx_beta (explicitly identical), ask_pipeworx_grounded, deep_research, and validate_claim all answer natural-language questions, while polymarket_arbitrage, polymarket_edges, polymarket_edge_tracker, polymarket_fill_risk, polymarket_kalshi_spread, and bet_research all analyze prediction markets. An agent would struggle to pick the correct tool without reading very long descriptions.

Naming Consistency3/5

All names are snake_case and readable, but the style is inconsistent: some are bare nouns (sequence, variation, homology), some are single verbs (lookup, recall, forget), and others are long descriptive phrases (scan_competitor_ai_presence, polymarket_kalshi_spread). There is no consistent verb_noun or resource_noun pattern across the set.

Tool Count2/5

38 tools is excessive for a coherent server, and nearly all of them are unrelated to the server's stated name ('Ensembl') — only about 7 tools (lookup, lookup_symbol, sequence, variation, vep, xrefs, homology) actually belong to the Ensembl domain. The rest form several unrelated clusters (Pipeworx data queries, prediction markets, memory, subscriptions), making the tool count feel bloated and unfocused.

Completeness2/5

For an Ensembl server, the surface is thin: it covers ID lookup, sequence retrieval, variants, VEP, xrefs, and homology, but omits other core Ensembl functionality such as gene trees, alignments, regulation, expression, and assembly data. Meanwhile the many non-Ensembl tools don't form a complete domain of their own — they are a grab bag of unrelated utilities.