Skip to main content
Glama

Security scan of a public GitHub repo

scan_repo

Scan a public GitHub repo before release to check pinned dependencies for advisories, assess build hygiene, and identify code leads for known bug classes in Solana or EVM projects.

Instructions

Use before a release or an integration: scans a public GitHub repo for advisories on its exact pinned dependencies (split into what ships on-chain and what is tooling), build hygiene, and code leads for known bug classes with file:line. ecosystem 'solana' for Rust/Anchor programs, 'evm' for Solidity (Foundry/Hardhat). Costs $0.50 USDC (Solana or Base). Waits up to wait_seconds for the report; otherwise returns jobId and accessToken for get_scan_report. A scan, not an audit.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
repoYeshttps://github.com/OWNER/REPO
ecosystemYes
wait_secondsNo

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Adds substantial context beyond the annotations: a concrete cost of $0.50 USDC and accepted payment rails (Solana or Base), the async contract (waits up to wait_seconds, otherwise returns jobId and accessToken), and an explicit scope disclaimer ('A scan, not an audit'). Annotations only cover readOnly/openWorld/idempotent hints, so this pricing and async-flow disclosure is genuinely additive.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loads the trigger condition, then scope, then ecosystem mapping, then cost, then async behavior, closing with the scope disclaimer. Every sentence carries distinct operational information; there is no filler or restatement of the name.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, but the description covers the two possible return shapes (inline report when the wait succeeds, jobId+accessToken otherwise) and points to get_scan_report for retrieval. With required params, enum meaning, cost, and async semantics all addressed, an agent has everything needed to invoke it correctly.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is only 33%, yet the description compensates: it maps the bare enum values to real meaning ('solana' for Rust/Anchor programs, 'evm' for Solidity with Foundry/Hardhat) and explains wait_seconds' behavioral consequence (report returned inline vs jobId/accessToken fallback). The repo parameter's public-repo constraint is also stated in prose, not just the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource (scans a public GitHub repo) and enumerates exactly what it produces: pinned-dependency advisories split by on-chain vs tooling, build hygiene, and file:line code leads for bug classes. This is clearly distinguishable from narrower siblings like dependency_advisories, and the closing line 'A scan, not an audit' bounds the deliverable.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly says when to use it ('before a release or an integration') and names get_scan_report as the continuation path when the wait window expires. It does not explicitly state when to avoid it in favor of siblings such as dependency_advisories or the watch_* tools, so it stops short of full when/when-not coverage.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.