Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
lookup_cveA

Fetch details, severity, and references for a CVE ID from NVD

check_packageA

Query OSV.dev for known vulnerabilities in a specific package + version. Requires the ecosystem (npm, PyPI, etc.) to disambiguate packages with the same name across registries.

scan_dependenciesB

Batch-check a list of named dependencies (with versions) against OSV.dev.

scan_dependency_fileA

Parse the raw contents of a package.json or requirements.txt file and check every listed dependency against OSV.dev.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.9/5.0

Scored across 4 tools

Disambiguation5/5

Each tool targets a clearly distinct use case: CVE lookup, single-package query, batch dependency scan, and manifest file parsing. The overlap between check_package and scan_dependencies is well-delineated by single-item vs. batch/list operations, so an agent should not misselect.

Naming Consistency5/5

All tool names follow a consistent verb_noun snake_case pattern with purposeful verbs: lookup, check, scan, scan. This makes the action and target of each tool predictable and easy to reason about.

Tool Count5/5

Four tools is a well-scoped set for a vulnerability lookup and dependency scanning server. Each tool earns its place and there is no redundancy or unnecessary bloat.

Completeness5/5

The tool surface covers the core vulnerability workflow: fetching CVE details, querying a single package, scanning a dependency list, and parsing a manifest file. No significant lifecycle or workflow gaps exist for the stated purpose.

Maintenance

ActivitySlowing
ResponsivenessNo issues