Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription
get_ecosystemsA
Get all supported ecosystems. An ecosystem is a package manager or repository for a specific language.

Returns:
Dictionary of ecosystems with the key being the ecosystem name and the value being the programming language / OS.

To use the ecosystem name in the query_package_cve function, you must use the exact ecosystem name as it is in the dictionary.
query_package_cveA
Query the OSV database for a package and return the CVE ID.
You can use this tool to get the CVE ID for a package. 
ALWAYS use it before installing packages to check if the package is vulnerable. For example in requirements.txt, pyproject.toml, uv.lock, etc.
You can also use it to check if the package is vulnerable before updating the package.

Args:
    package: The package name to query
    version: The version of the package to query, can be None if you want to query all versions
    ecosystem: The ecosystem of the package to query, can be None if you want to query all ecosystems. 
    
    * For supported ecosystems, see the get_ecosystems tool.

Returns:
    A list of CVE IDs
query_for_cve_affectedB
Query the OSV database for a CVE and return the affected versions.

Args:
    cve: The CVE ID to query

Returns:
    A list of affected versions
query_for_cve_fix_versionsB
Query the OSV database for a CVE and return the fix versions.

Args:
    cve: The CVE ID to query

Returns:
    A list of fix versions

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.8/5.0

Scored across 4 tools

Disambiguation5/5

Each tool has a clearly distinct purpose with no overlap: get_ecosystems retrieves ecosystem metadata, query_for_cve_affected and query_for_cve_fix_versions handle CVE-specific queries for affected and fixed versions respectively, and query_package_cve checks packages for vulnerabilities. The descriptions make it easy to differentiate between them, especially the two CVE-related tools that focus on different aspects of vulnerability data.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern with snake_case: get_ecosystems, query_for_cve_affected, query_for_cve_fix_versions, and query_package_cve. The naming is predictable and readable, with 'query' used for database lookups and 'get' for metadata retrieval, maintaining a coherent style throughout the set.

Tool Count4/5

With 4 tools, the count is reasonable for a vulnerability database server, covering core operations like ecosystem listing, CVE queries, and package checks. It feels slightly thin but well-scoped, as each tool serves a specific function without redundancy. A few more tools (e.g., for batch queries or detailed vulnerability info) could enhance it, but the current set is functional and appropriate.

Completeness4/5

The tool surface covers essential workflows for OSV database interactions: retrieving ecosystems, querying CVEs for affected and fixed versions, and checking packages for vulnerabilities. Minor gaps exist, such as no tool for listing all CVEs or querying by date/severity, but agents can work around this by combining existing tools. The set provides a solid foundation for vulnerability assessment tasks.

Maintenance

ActivityInactive
ResponsivenessNo issues