Skip to main content
Glama

DepScout

Check a dependency list

check_dependencies
Read-onlyIdempotent

Check up to 50 packages at exact versions (for example from package.json, package-lock.json, requirements.txt, go.mod, pom.xml, Cargo.toml or a .csproj) against OSV.dev in one batch. Returns a summary count and only the packages with problems: malicious-package flags first, then vulnerabilities by severity with the version that fixes each and the minimum upgrade target. Use when the user pastes a dependency file or list, or asks to "audit my dependencies" or "check my package.json / requirements.txt", or which dependencies are vulnerable or outdated. Entries without an exact version are skipped and listed; transitive dependencies are only checked if included in the list.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packagesYesPackages to check, each with name and exact version
ecosystemNoDefault ecosystem for all entries. Package ecosystem: npm, PyPI, Go, Maven, crates.io or NuGet (aliases like pip, python, cargo, rust, golang, java, dotnet also work)

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations cover the safety profile (readOnly, idempotent, non-destructive), and the description adds substantial behavior beyond them: return shape (summary count plus only problem packages, malicious flags first, then severity-ordered vulns with fix versions and minimum upgrade targets), the 50-entry batch limit, and that version-less entries are skipped and listed while transitive deps are checked only if listed.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single dense paragraph that front-loads the verb, scope, and batch limit before usage triggers and edge-case behavior. Every sentence carries information, though it is packed enough that the usage guidance and ordering rules could be separated for faster scanning.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description compensates by describing the return format in detail, and it covers ecosystem defaults, entry limits, and skip behavior. An agent has everything needed to invoke and interpret this tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3, but the description adds semantics not present in the schema: the exact-version requirement and the explicit skip-and-list behavior for entries lacking an exact version, plus reinforcement of the 50-item cap.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (check), resource (packages at exact versions), scope (up to 50 in one batch), and the external authority (OSV.dev). The batch framing implicitly distinguishes it from single-package siblings like check_package, so an agent can tell which tool to reach for.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives concrete triggers — pasted dependency file/list, 'audit my dependencies', 'check my package.json/requirements.txt', or vulnerable/outdated questions — plus the file types it accepts. It does not name sibling tools or state when-not to use it, so it stops short of full routing guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources