Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
scan_projectA

Read a local project and return mechanical Build Readiness signals: file and line counts, languages, test files, CI config, lockfile, docs, and a redacted scan for hardcoded secrets. Returns signals only, never your source. Run this first.

run_testsA

Run the project's test suite on this machine and parse pass/fail counts. This EXECUTES the project's own test command (for example npm test, which runs whatever that script defines), so only approve it for a project you trust to run. Your host asks before it runs. A green suite is the strongest grade-A reliability evidence the Obra CTO Score can use. Pass the result numbers to score_build_readiness.

check_dependenciesA

Query OSV.dev for known vulnerabilities in the project's locked dependencies, using exact versions from package-lock.json. Only package names and versions are sent, never your code. Real, current CVE data. Feed any findings into your security assessment.

prepare_code_reviewA

Select the highest-signal files (security-relevant paths, entry points, large files) and return their contents on this machine, with a review checklist. YOU, the host model, then read them and produce a structured security and architecture assessment, which you pass to score_build_readiness as qualitative. This is what upgrades those dimensions from inferred (grade C) to verified (grade A). Files stay local.

score_build_readinessA

Produce the Obra CTO Score (0 to 100) with a per-dimension breakdown, evidence grades, and a Top Risks register. Scan runs automatically. If you ran run_tests first, pass its numbers so reliability becomes grade-A evidence.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.4/5.0

Scored across 5 tools

Disambiguation5/5

Each tool has a distinct, non-overlapping purpose: scanning project signals, running tests, checking dependencies, preparing code review data, and producing the final score. Clear boundaries prevent misselection.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern (e.g., scan_project, run_tests) using snake_case, making the set predictable and easy to navigate.

Tool Count5/5

Five tools cover the full workflow of build readiness assessment without redundancy. The count is well-scoped for the domain, neither too sparse nor excessive.

Completeness5/5

The tool set covers the entire lifecycle: initial scanning, testing, vulnerability checking, in-depth code review preparation, and final scoring. No obvious gaps for its stated purpose.

Maintenance

ActivityInactive
ResponsivenessNo issues