Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
VERACODE_API_IDYesYour Veracode API ID, generated in Veracode > Account Settings > API Credentials.
VERACODE_API_SECRETYesYour Veracode API Secret, generated in Veracode > Account Settings > API Credentials.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
veracode_applicationsC

List and search Veracode application profiles

veracode_findingsC

Get vulnerability findings/flaws for a Veracode application

veracode_scan_statusC

Get scan status and summary report for a Veracode application

veracode_policy_complianceC

Check policy compliance status for Veracode applications

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.4/5.0

Scored across 4 tools

Disambiguation5/5

Each tool has a clearly distinct purpose targeting different aspects of the Veracode security platform: applications management, vulnerability findings, policy compliance, and scan status. There is no overlap or ambiguity between these four functions.

Naming Consistency5/5

All tool names follow the exact same pattern: 'veracode_' prefix followed by a descriptive noun phrase (applications, findings, policy_compliance, scan_status). This creates perfect consistency and predictability across the toolset.

Tool Count4/5

Four tools is a reasonable count for a security scanning platform interface, though it feels slightly minimal. The tools cover core functions but might benefit from additional operations like initiating scans or managing scan configurations.

Completeness4/5

The toolset provides good coverage for monitoring and reporting on Veracode security scans, including applications, findings, compliance, and status. However, there are minor gaps in action-oriented operations like initiating new scans or managing scan configurations that would complete the workflow.

Maintenance

ActivityInactive
ResponsivenessNo issues