Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
GITHUB_TOKENYesYour GitHub Personal Access Token (PAT) with at least 'repo' and 'security_events' scopes, or fine-grained token with read-only access to Code scanning alerts, Dependabot alerts, and Metadata.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
check_ci_statusA

Fetches recent CI/CD workflow runs (GitHub Actions) for a GitHub repository.

  • Side effects: None. This is a strictly read-only operation.

  • Data sources: GitHub REST API (actions/runs).

  • Auth requirements: No authentication required for public repositories. Uses configured token if available.

  • Rate limits: Subject to standard GitHub API limits.

  • Return shape: Returns a JSON array of workflow runs including name, status, conclusion, head_branch, created_at, updated_at, and html_url.

  • Usage guidelines: Use this tool ONLY to check raw GitHub Actions workflow history and CI build statuses. DO NOT use this tool for other analyses:

    • For a computed A-F health score grading, use 'get_health_score' instead.

    • For retrieving basic repository stats (stars, forks), use 'get_repo_health' instead.

    • For calculated DORA metrics, use 'get_dora_metrics' instead.

get_repo_healthA

Fetches basic repository metadata and statistics from the public GitHub API.

  • Side effects: None. This is a strictly read-only operation.

  • Data sources: Public GitHub REST API (GET /repos/{owner}/{repo}).

  • Auth requirements: No authentication required for public repositories. Uses configured GitHub token if available.

  • Rate limits: Subject to standard GitHub API limits (60 requests/hour unauthenticated, 5000 requests/hour authenticated).

  • Return shape: Returns a JSON object containing specific metadata: full_name (string), description (string), stargazers_count (number), open_issues_count (number), language (string), license (string, SPDX ID), pushed_at (ISO 8601 string), default_branch (string), archived (boolean), and forks_count (number).

  • Usage guidelines: Use this tool ONLY to retrieve basic raw metadata (like stars, forks, language, and issue counts). DO NOT use this tool for other specific analyses:

    • For a computed A-F health score grading, use 'get_health_score' instead.

    • For checking CI/CD workflow run statuses, use 'check_ci_status' instead.

    • For package vulnerabilities and dependency graph, use 'analyze_dependencies' instead.

    • For code security and static analysis, use 'analyze_code_scanning' instead.

analyze_dependenciesA

Fetches Dependabot alerts for a GitHub repository to analyze vulnerable package dependencies.

  • Side effects: None. This is a strictly read-only operation.

  • Data sources: GitHub REST API (dependabot/alerts).

  • Auth requirements: Requires GITHUB_TOKEN with appropriate permissions (dependabot alerts are often restricted).

  • Rate limits: Subject to standard GitHub API limits.

  • Return shape: Returns a JSON array of vulnerable package dependencies including summary, severity, package_name, state, and html_url.

  • Usage guidelines: Use this tool ONLY to find vulnerable package dependencies (npm, pip, etc.). DO NOT use this tool for other checks:

    • For static code security vulnerabilities (CodeQL), use 'analyze_code_scanning' instead.

    • For a computed A-F health score grading, use 'get_health_score' instead.

analyze_code_scanningA

Fetches or triggers open Code Scanning (CodeQL) alerts for a GitHub repository.

  • Side effects: Read-only by default. If trigger_scan=true, writes to GitHub Actions by creating a workflow_dispatch event.

  • Data sources: GitHub REST API (code-scanning/alerts and actions).

  • Auth requirements: Requires GITHUB_TOKEN with appropriate permissions (security-events).

  • Rate limits: Subject to standard GitHub API limits.

  • Return shape: Returns a JSON array of alert objects including rule_id, severity, rule_description, state, location paths, and html_url.

  • Usage guidelines: Use this tool ONLY for deep static code vulnerability scanning (CodeQL). DO NOT use this tool for other checks:

    • For package/dependency vulnerabilities, use 'analyze_dependencies' instead.

    • For a computed A-F health score grading, use 'get_health_score' instead.

    • For checking standard CI/CD workflow statuses, use 'check_ci_status' instead.

get_health_scoreA

Calculates a 0-100 health score and A-F grade for a GitHub repository.

  • Side effects: Writes a trend snapshot to local disk for history tracking. Read-only against GitHub API.

  • Data sources: GitHub REST API (repos, actions, dependabot) and OpenSSF Scorecard API.

  • Auth requirements: No authentication required for public repositories. Uses configured token if available.

  • Rate limits: Subject to standard GitHub API limits (heavy usage across multiple endpoints).

  • Return shape: Returns a JSON object with a grade (A-F), total score, detailed category breakdown (CI, freshness, security, community, maintenance), improvement suggestions, and historical trend data.

  • Usage guidelines: Use this tool ONLY for deep analytical grading and overall repository health assessment. DO NOT use this tool for quick metadata checks:

    • For basic raw metadata (stars, language, etc.), use 'get_repo_health' instead.

    • For raw CI workflow statuses, use 'check_ci_status' instead.

    • For deep code vulnerability scanning, use 'analyze_code_scanning' instead.

    • For DORA metrics, use 'get_dora_metrics' instead.

get_dora_metricsA

Calculates DORA proxy metrics (deployment frequency, lead time, change failure rate, MTTR) for a GitHub repository.

  • Side effects: None. This is a strictly read-only operation.

  • Data sources: GitHub REST API (releases, actions/runs, pulls).

  • Auth requirements: No special authentication required for public repositories. Private repositories require GITHUB_TOKEN.

  • Rate limits: Subject to standard GitHub API limits. Heavy API usage due to multiple list endpoints being queried.

  • Return shape: Returns a JSON object with calculated DORA metrics over the specified period.

  • Usage guidelines: Use this tool ONLY to evaluate DORA metrics and team delivery performance. DO NOT use this tool for other checks:

    • For raw workflow statuses, use 'check_ci_status' instead.

    • For a computed A-F health score grading, use 'get_health_score' instead.

    • For general repository metadata, use 'get_repo_health' instead.

compare_reposA

Compares health scores of multiple GitHub repositories (2-5 repos) and ranks them.

  • Side effects: None. This is a strictly read-only operation.

  • Data sources: GitHub REST API and OpenSSF Scorecard API (via get_health_score logic).

  • Auth requirements: No authentication required for public repositories. Uses configured token if available.

  • Rate limits: Subject to standard GitHub API limits. Multiplies API calls by the number of repositories compared.

  • Return shape: Returns a JSON object containing a ranked list of repositories (owner, repo, rank) with their detailed health breakdown (score, CI, freshness, security, community, maintenance).

  • Usage guidelines: Use this tool ONLY when you need to compare or rank multiple repositories against each other based on their health scores. DO NOT use this tool for analyzing a single repository:

    • For getting the health score of a single repository, use 'get_health_score' instead.

    • For comparing raw metadata instead of health scores, query 'get_repo_health' individually.

check_best_practicesA

Checks whether a GitHub repository follows open-source community best practices.

  • Evaluates 12 checks: README, LICENSE, SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT, issue/PR templates, branch protection, Dependabot, CI/CD, description, and topics.

  • Returns a weighted 0-100 score with A-F grade, per-check pass/fail/unknown status, and actionable suggestions for missing items.

  • Side effects: None. Read-only operation.

  • Rate limits: ~6 GitHub API calls per invocation.

  • Branch protection check requires admin access — returns "unknown" (not penalized) if token lacks permission.

  • Use this tool to audit repo quality and discoverability. For a computed health grade based on CI/security/activity, use 'get_health_score' instead.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.4/5.0

Scored across 8 tools

Disambiguation4/5

Most tools have clearly distinct purposes, and the descriptions include explicit cross-references to prevent misuse. However, get_repo_health vs get_health_score and check_best_practices vs get_health_score have partially overlapping outputs (scores/grades/heuristics), which could cause an agent to pick the wrong one without careful reading.

Naming Consistency4/5

All tools follow a verb_noun pattern, and verbs loosely map to action types: analyze for vulnerability scanning, check for status/best practices, get for metrics/metadata, and compare for ranking. The main inconsistency is that get_repo_health and get_health_score sound very similar despite returning different kinds of data, and check_best_practices could plausibly have been named get_best_practices.

Tool Count5/5

Eight tools is well-scoped for a GitHub repository health/analytics server. Each tool covers a distinct analysis dimension, and none feel redundant or extraneous.

Completeness5/5

The tool set covers the domain thoroughly: raw metadata, CI status, security scanning (CodeQL and Dependabot), best practices, DORA metrics, composite health scoring, and multi-repo comparison. No major workflow dead ends or obvious missing operations for a read-heavy health assessment server are apparent.

Maintenance

ActivityMaintained
ResponsivenessUnresponsive