Skip to main content
Glama

DepScout

Get vulnerability details

get_vulnerability
Read-onlyIdempotent

Look up one vulnerability or malicious-package advisory by ID (CVE, GHSA, PYSEC, GO, RUSTSEC, MAL and other OSV IDs) and return its summary, severity, CVSS vector, aliases, publish date, the affected packages with their affected and fixed version ranges, and key references. Use when the user mentions a specific advisory or CVE ID ("what is CVE-2021-44228?", "am I affected by this GHSA?") and wants to know what it is, what is affected or which version fixes it. Only covers advisories in OSV.dev.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
idYesAdvisory ID, e.g. CVE-2021-44228, GHSA-29mw-wpgm-hmr9, PYSEC-2018-28, MAL-2025-20690

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly, idempotent, non-destructive and openWorld, so the safety profile is covered. The description adds genuinely new behavior: the exact fields returned (severity, CVSS vector, aliases, publish date, affected packages with affected/fixed ranges, references) and a coverage boundary ('Only covers advisories in OSV.dev'), which tells the agent when a lookup will come back empty.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Purpose is front-loaded, followed by the return payload, then the usage trigger, then the scope caveat. Three sentences with no filler; the return-field enumeration is dense but justified given there is no output schema to carry it.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description carries the return-value burden and does so explicitly (summary, severity, CVSS vector, aliases, dates, version ranges, references). Combined with the OSV.dev coverage boundary and a concrete usage trigger, an agent has everything needed to decide and call correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and the schema already supplies ID examples, so the baseline is 3. The description goes slightly beyond by enumerating additional ID namespaces (GO, RUSTSEC, MAL, 'other OSV IDs'), clarifying that the single 'id' field accepts any OSV ecosystem identifier rather than just CVEs.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('look up one vulnerability or malicious-package advisory by ID') and immediately enumerates the accepted ID namespaces (CVE, GHSA, PYSEC, GO, RUSTSEC, MAL). The single-advisory-by-ID framing clearly separates it from the package/lockfile/dependency checking siblings, which operate on project manifests rather than a named advisory.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives an explicit trigger with real user phrasings ('what is CVE-2021-44228?', 'am I affected by this GHSA?') and the intent behind the call (what it is, what is affected, which version fixes it). No sibling tool is named as an alternative, so the routing guidance is context-rich but not exhaustive.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources