Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint, idempotentHint, openWorldHint, and destructiveHint false. The description adds valuable behavioral context: partial failures degrade gracefully, bundlephobia's first measurement can take 5-30 seconds, and sources_failed will list any timeout.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is longer than typical but well-structured: it front-loads the core purpose, then details the return format, constraints, and failure behavior. Every sentence adds value, though slightly verbose.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite having no output schema, the description fully explains the return format (summary block, per-advisory detail, links, alternative versions) and handles edge cases (partial failures, timeout behavior). Highly informative for a composite tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already explains both parameters. The description adds marginal value by explicitly noting that scoped packages are accepted for the 'package' parameter, which goes beyond the schema's basic description.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb structure ('composite check') and clearly identifies the resource (npm package) via two external APIs. It distinguishes from siblings by noting that other ecosystems (PyPI, Maven, etc.) fall under a different tool (deps.dev:version).

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit usage criteria are provided: 'Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me"'. It also states NPM-only in v1 and directs to an alternative for other ecosystems.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.5/5.0
Disambiguation2/5

Many tools have overlapping purposes (e.g., ask_pipeworx, ask_pipeworx_beta, ask_pipeworx_grounded all serve similar query routing). Tools from unrelated domains (UK Gazette, Polymarket betting, AI visibility checks) are mixed together, making it hard for an agent to distinguish which tool to use for a given task.

Naming Consistency1/5

Naming is chaotic: some tools use descriptive phrases with underscores (gazette_deceased_estates, polymarket_arbitrage), others use generic verbs (remember, recall, forget), and some include version or mode indicators (ask_pipeworx_beta, scan_competitor_ai_presence). No consistent pattern across the set.

Tool Count2/5

With 36 tools, the server is overstuffed for its purported focus on the UK Gazette. The majority of tools (Polymarket, Pipeworx general, AI visibility, etc.) are unrelated to the server's name, making it feel like a bundling of many services into one, which is excessive for a coherent tool set.

Completeness2/5

For a server named 'Uk Gazette', there are only a handful of Gazette-specific tools (gazette_search_notices, gazette_insolvency_notices, etc.), while the rest cover unrelated domains. This leaves obvious gaps for Gazette-related tasks (e.g., no tool for searching particular notice types or filtering by edition), despite the large tool count.