Skip to main content
Glama
EricSeokgon

egovframe-scaffold-mcp

by EricSeokgon

의존성 점검

check_egovframe_dependencies
Read-onlyIdempotent

Analyze Maven/Gradle dependencies in eGovFrame projects against official 5.x baselines, Spring Boot BOM, and RTE modules; classify compliance and report security settings without file changes.

Instructions

프로젝트의 Maven/Gradle 의존성(resolve=true 면 빌드 도구로 해석한 전이 의존성까지, 트리 경로와 선언·해석 버전 차이 포함)을 공식 5.x parent(egovframe-web-config-parent·egovframe-boot-starter-parent)가 관리하는 기준 버전, Spring Boot BOM 전체(spring-boot-dependencies + import 한 단계), RTE 모듈 18종의 전이 의존성과 대조해 기준 충족/기준 미만/parent 관리/전환 대상(3.x·4.x RTE, javax 좌표)/교체 필요(DBCP 1.x·Log4j 1.x·Jackson 1·Ehcache 2 등)/벤더 배포(국내 DBMS·GPKI 등)/기준 없음 으로 분류하고 항목마다 기준 출처(parent 직접·계열·Boot BOM·RTE 전이)를 적으며, 5.x parent 사용 여부와 Java 버전, 보안 설정 존재 여부(sec.security 컴포넌트·CSRF·XSS 필터·보안 헤더·HTTPS 저장소)를 파일·라인 근거와 함께 보고합니다. 기본은 오프라인(동봉 기준 catalog/dependency-baseline.json)이며 offline=false 일 때만 OSV(api.osv.dev)로 알려진 취약점을 조회합니다. 디스크를 변경하지 않습니다.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
formatNo출력 형식markdown
offlineNotrue(기본)면 네트워크 없이 기준 대조만, false 면 OSV 취약점 조회 추가
resolveNotrue 면 빌드 도구(Maven dependency:tree / Gradle dependencies)로 전이 의존성까지 해석해 함께 판정(빌드 도구·저장소 접근 필요, 수십 초)
projectDirYes점검할 프로젝트 디렉터리(절대경로 권장)
resolveScopeNoresolve 범위: runtime(compile+runtime, 기본) | all(test·provided 포함)runtime
resolveTimeoutMsNo해석 명령 타임아웃(ms)

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
javaYes
notesYes
checksYes
parentYes
offlineYes
summaryYes
baselineYes
findingsYes
osvErrorNo
projectDirYes
resolutionNo
buildSystemYes
vulnerabilitiesNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.36.1

TDQS

A3.9/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already cover readOnly/idempotent/non-destructive, and the description adds real value beyond them: it guarantees '디스크를 변경하지 않습니다', explains the default offline catalog path versus OSV network access only when offline=false, and flags that resolve=true needs build-tool/repo access and takes tens of seconds. This is meaningful operational context, though it could note permissions or rate behavior more explicitly.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The tool's purpose is front-loaded, but the core content is a single very dense multi-clause Korean sentence enumerating eight classification buckets and four baseline sources, which is hard to parse and could be structured as a list. It earns its length informationally but is not concise in form.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given an output schema and full annotation coverage, the description is unusually complete: it enumerates the classification outcomes, the baseline provenance it will cite, the security-config checks, and the offline/online toggle. An agent has everything needed to decide and to interpret results.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already defines every parameter including defaults and enums. The description only restates resolve/offline semantics with slightly more detail (전이 의존성, 트리 경로, 선언·해석 버전 차이) and adds no syntax or format nuance the schema lacks.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a precise verb ('점검') and a tightly bounded resource (Maven/Gradle 의존성) along with the exact classification taxonomy and baseline sources it compares against. The scope is narrow enough that an agent can separate it from broader siblings like diagnose_egovframe_project without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It implies usage ('프로젝트의 의존성' 점검) and explains the cost/behavior toggles (resolve, offline), but never states when to prefer this over diagnose_egovframe_project, validate_egovframe_project, or generate_egovframe_sbom, nor any when-not condition.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.