Skip to main content
Glama

typosquat_check

Read-onlyIdempotent

Call before installing a package whose name you typed or recalled. Checks whether an npm or PyPI package name is a near-miss of a well-known package (typosquatting), with an edit-distance threshold scaled to name length; names of 3 characters or fewer are not fuzzy-matched. Uses a curated list of popular names, so a clean result does not prove a package is safe. It does not check that the package exists: supply_chain_check does.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesPackage name to check for likely typosquatting of a well-known package in the given ecosystem.
ecosystemYesPackage ecosystem, e.g. npm or PyPI.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changed
    • changedInput schema / properties / ecosystem / description
      Previous value: -""New value: +"Package ecosystem, e.g. npm or PyPI."
    • changedInput schema / properties / package / description
      Previous value: -""New value: +"Package name to check for likely typosquatting of a well-known package in the given ecosystem."
  2. First observed

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare read-only, idempotent, non-destructive behavior, so the bar is lower, yet the description still adds substantive behavior: an edit-distance threshold scaled to name length, a >=3-character matching cutoff, and a curated-list limitation warning that a clean result does not prove safety. It also discloses a negative scope (does not verify existence), which is exactly the kind of boundary an agent needs.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences, each earning its place: the first is the call trigger, the second the mechanism, the third the caveat plus the hand-off to supply_chain_check. Front-loaded with the action, no filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a two-parameter, read-only lookup with no output schema, the description supplies everything an agent needs: when to call, how the check works, its precision limits, and where to go for the complementary existence check. Return-value semantics are implied ('a clean result does not prove a package is safe').

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% for both parameters, so the baseline is 3; the description earns a step above by naming the concrete ecosystems ('npm or PyPI') and framing the package parameter as the name to be fuzzy-matched in that ecosystem, which reinforces the pairing between the two required params.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource (checks whether a package name is a near-miss of a well-known package, i.e. typosquatting) and scopes it to npm or PyPI. It also explicitly demarcates itself from the sibling supply_chain_check, so an agent can route without opening either schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives an explicit trigger ('Call before installing a package whose name you typed or recalled'), a when-not edge case (names of 3 characters or fewer are not fuzzy-matched), and names the alternative tool for the adjacent question (existence) via supply_chain_check. Nothing is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.