Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
DEPS_ROOTNoProject root directory to use when not passed by the chat
GITHUB_TOKENNoGitHub token for higher advisory rate limits

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
deps_detectB

Detect npm, Maven, and Python manifests in a project directory.

deps_npm_auditA

Run npm audit --json and return severity counts plus the first 40 packages.

deps_maven_treeC

Run mvn dependency:tree for a pom.xml in this directory or one level down.

deps_python_packagesC

List declared Python packages from requirements.txt or show pyproject.toml.

deps_github_advisoryC

Look up GitHub security advisories. ecosystem is npm, maven, pip, or nuget.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.3/5.0

Scored across 5 tools

Disambiguation5/5

Each tool targets a distinct purpose: manifest detection, npm audit, Maven dependency tree, Python package listing, and GitHub advisory lookup. No overlap or ambiguity between tools.

Naming Consistency5/5

All tools use a consistent 'deps_' prefix followed by a verb_noun pattern (e.g., deps_npm_audit, deps_maven_tree). Naming is uniform and predictable.

Tool Count5/5

With 5 tools covering detection, language-specific inspection, and advisory lookup, the count is well-scoped for a dependency scanning server—neither sparse nor bloated.

Completeness3/5

The surface covers detection and some language-specific commands, but lacks unified vulnerability scanning across all ecosystems (e.g., no Python audit, no Maven audit) and no update/fix operations. Advisory lookup partially fills this, but gaps remain.

Maintenance

ActivityMaintained
ResponsivenessNo issues