Skip to main content
Glama

verify_dependencies

Verify that every external dependency in code or diffs exists on PyPI or npm, catching hallucinated package names and slopsquatting supply-chain risks.

Instructions

Verify that every external dependency introduced by code or a diff actually exists on its public registry - the mechanical half of gate G4 (Dependency Honesty). LLMs hallucinate package names and attackers register them (slopsquatting), so a missing registry entry is both an incompleteness defect and a supply-chain risk. Extracts imports (Python via AST incl. importlib/import literals; JS/TS via import/require specifiers), classifies stdlib/Node built-ins/first-party-in-diff/excluded locally, then checks the rest against PyPI (PEP 503) and the npm registry. NETWORK NOTICE: this is the only tool here that touches the network - package names and nothing else are sent over HTTPS, bounded (50 packages/call, 10s timeout, 3 attempts). Verdicts: FAIL = something does not exist (hallucinated/misspelled); REVIEW = unverifiable (offline/registry errors - never silently passed); PASS = everything resolves. Existence only: version pinning and integrity stay with the reviewer.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
codeNoSource text to extract imports from (requires 'language').
diffNoUnified diff; imports are extracted from added lines of Python/JS/TS files with new-file line numbers. Exactly one of 'code' and 'diff'.
excludeNofnmatch globs for package names that must never be sent to a registry (private/internal packages).
languageNoLanguage of 'code'.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv3.6.0

TDQS

A4.4/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden and does so: it discloses that it is the only networked tool, exactly what data leaves (package names only, over HTTPS), hard limits (50 packages/call, 10s timeout, 3 attempts), and the three verdict semantics including the safety-critical 'REVIEW = unverifiable... never silently passed'. It also states the deliberate scope boundary (existence only).

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with purpose then rationale, extraction mechanics, the network notice, the verdict legend, and the scope limit. Every clause is information-bearing, though the parenthetical on importlib/__import__ literals and the enumerated caps make it denser than strictly necessary for selection.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description must explain returns and does so via the PASS/FAIL/REVIEW verdict legend, while also covering extraction sources, network exposure, and the explicit exclusion of version pinning and integrity. Nothing an agent needs to call it correctly is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3 and the schema already documents 'code' requiring 'language', the diff/new-file line-number behavior, and the fnmatch glob semantics of 'exclude'. The description reinforces the security intent of 'exclude' (names that must never be sent to a registry) but adds no syntax or format detail beyond the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource (verify external dependencies exist on their public registry) and pins it to a named gate (G4, Dependency Honesty). It also explicitly distinguishes itself from every sibling by declaring it is 'the only tool here that touches the network', so an agent can route to it without opening other schemas.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Gives clear context for when to reach for it (the mechanical half of gate G4, after code or a diff introduces imports) and scopes what it is not for (version pinning and integrity 'stay with the reviewer'). It does not name a specific alternative sibling or an explicit when-not-to-use branch, which keeps it just short of a 5.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.