Skip to main content
Glama

๐Ÿฅ— PkgDiet

npm version npm downloads License: MIT Node.js >=18 PkgDiet MCP Server Score

Put your node_modules on a diet.

PkgDiet is a proactive dependency governance tool that helps you find unused dependencies, analyze package health, and reduce node_modules size. It doesn't just ask "is it safe?" โ€” it asks "is it optimal?"

Our Vision: PkgDiet's mission is to become an open standard for dependency intelligence in AI-assisted software development. Our goal is simple: whenever a developer, CI pipeline, or compatible AI agent needs to evaluate, install, replace, or audit a dependency, PkgDiet should provide trusted, machine-readable insights through transparent, opt-in integrations.


Quick Start

Run it instantly in any Node.js project (no installation required):

npx pkgdiet

To clean up unused dependencies automatically:

npx pkgdiet --fix

Related MCP server: dependency-health-mcp

What You Get

PkgDiet scans your codebase's AST and NPM registry data in seconds to give you a pristine, actionable report:

- Scanning imports...
โœ“ Scanned 141 files, found 54 imports
- Checking health of 44 packages...
โœ“ Health check complete: 10 issues found
- Analyzing dependency sizes...
โœ“ Size analysis complete: 40.5 MB total

โ•ญโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฎ
โ”‚ ๐Ÿฅ— PkgDiet v1.2.3                                    โ”‚
โ”‚ Put your node_modules on a diet...                   โ”‚
โ”‚ Project: express                                     โ”‚
โ”‚ Dependencies: 44 direct โ”‚ 141 files scanned          โ”‚
โ”‚ node_modules: 40.5 MB                                โ”‚
โ”‚    Overall Score:  67/100  โš ๏ธ                        โ”‚
โ”‚    โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘                    โ”‚
โ•ฐโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฏ

๐Ÿ—‘๏ธ  UNUSED DEPENDENCIES (1 found โ€” saves ~21.2 KB)
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
   โšซ hbs                      dev      21.2 KB      โ†’ npm uninstall hbs

๐Ÿฅ  HEALTH WARNINGS (10 issues)
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
   Package                    Score    Issue
   โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
   ๐Ÿ”ด pbkdf2-password          29       Unmaintained (4yr) ยท Single maintainer ยท Low downloads
   ๐Ÿ”ด encodeurl                57       Unmaintained (2yr)
   ๐ŸŸก once                     70       Single maintainer

๐Ÿ“ฆ  SIZE ANALYSIS
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
   Package                      Install Size    % of node_modules
   โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
   ๐ŸŸง eslint                     2.77 MB         6.8%
   ๐ŸŸง mocha                      2.22 MB         5.5%
   โœ“  42 other packages under 5% โ€” no action needed

๐Ÿ’ก  BETTER ALTERNATIVES (1 suggestion)
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
   ๐Ÿ”Œ body-parser โ†’ express.json() built into Express 4.16+, no separate install needed

โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
  Action summary: 1 to remove ยท 10 to investigate ยท 1 to swap
  Run pkgdiet --fix to remove unused ยท --json for full machine-readable output

Features

  • AST-Based Unused Detection: Safely flags installed packages that are never imported (handles TypeScript, JSX, dynamic imports, and NPM scripts).

  • Health & Rot Scoring: Detects the "Bus Factor" (single maintainer) and abandoned packages before they become technical debt.

  • Smart Alternatives: Recommends modern, lightweight replacements for legacy bloat (e.g., dayjs instead of moment, picocolors instead of chalk).

  • Pre-Install Gate: Run pkgdiet check <package> to evaluate a library before adding it to your project.

  • MCP Server for AI Agents: Give compatible AI coding assistants the ability to evaluate dependency health using PkgDiet's machine-readable data before recommending or installing packages. Install globally in one click: npx pkgdiet mcp-install

  • CI/CD Ready: Use pkgdiet ci to parse package-lock.json diffs in GitHub Actions and block PRs that introduce unhealthy dependencies.


Configuration

PkgDiet works out of the box with zero configuration. However, teams can enforce custom policies by running npx pkgdiet init to generate a .pkgdietrc.json:

{
  "minHealthScore": 60,
  "maxNodeModulesSizeMB": 300,
  "ignoreRules": ["chalk"],
  "telemetry": false
}

Telemetry (Local Only)

By default, PkgDiet writes anonymous, purely local usage metrics to a .pkgdiet-metrics.json file in your repository to track the amount of time and disk space saved. No data is ever sent off your machine. You can disable this local logging entirely by adding "telemetry": false to your .pkgdietrc.json or by setting the PKGDIET_TELEMETRY_DISABLED=1 environment variable.


Commands

Command

Description

npx pkgdiet

Run full repository audit

npx pkgdiet --fix

Preview unused dependencies and apply approved removals

npx pkgdiet check <pkg>

Check health/size of a single package

npx pkgdiet init

Generate config and GitHub Actions workflows

npx pkgdiet ci

Run PR gate checks based on lockfile diffs

npx pkgdiet mcp

Start the JSON-RPC server for AI agents

npx pkgdiet mcp-install

Auto-configure MCP for Claude Desktop


License

MIT ยฉ Om Tajne

Available Tools

3 tools
check_dependencyA

Check a dependency (e.g. npm package) for health, risk, and cost before installing.

ParametersJSON Schema
NameRequiredDescriptionDefault
packageYes

TDQS

A3.7/5.0
Behavior3/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full burden of disclosing behavior. The phrasing 'check ... before installing' implies a read-only, non-mutating operation, which is useful. However, it does not describe the output format, whether the check contacts a registry/network, auth requirements, or possible side effects.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A single sentence with no filler. It front-loads the operation, states the resource, and enumerates what is checked. Every word contributes to the agent's understanding.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool is simple (one required string, no nested objects), and the description covers what it checks and when to use it. However, since there is no output schema, the description should say more about what the agent will receive back; 'health, risk, and cost' implies the result dimensions but not their shape or interpretation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The schema only declares 'package' as a required string with no description. The tool description adds meaning by identifying the value as a dependency such as an npm package. It does not, however, specify accepted formats (e.g. bare name vs. versioned specifier), so it only partially compensates for 0% schema description coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb 'Check' and the resource 'a dependency', and it names the evaluation dimensions: health, risk, and cost. It also gives an example ('npm package') and a usage stage ('before installing'). It stops short of 5 because it does not explicitly contrast this tool with its siblings suggest_alternative and get_policy.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'before installing' provides clear usage context: this is a pre-install evaluation tool. It does not, however, state when not to use it or explicitly point to suggest_alternative or get_policy as alternatives, so it misses the highest bar.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

get_policyA

Get the active PkgDiet dependency policy for this repository.

ParametersJSON Schema
NameRequiredDescriptionDefault

No parameters

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

There are no annotations, so the description itself must convey behavior. 'Get' clearly signals a read-only retrieval, and the zero-parameter shape means there is no input-triggered side-effect risk. It does not disclose error or missing-policy behavior, but for a simple getter this is mostly sufficient.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single concise sentence that immediately states the action, target, and scope. There is no filler, repetition, or unnecessary detail.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a zero-parameter, no-output-schema getter, the description is sufficiently complete: an agent can invoke it without further setup and can infer that the return value is the active policy. No additional prerequisites or edge cases are necessary to understand the call.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The tool has zero parameters and the schema description coverage is effectively 100%. The baseline for a zero-parameter tool is 4, and the description adds no conflicting or missing parameter information.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('Get') and a clearly identified resource ('active PkgDiet dependency policy for this repository'). This is distinct from the sibling tools check_dependency and suggest_alternative, which imply different actions.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies that this tool should be used when the active policy needs to be retrieved, and it scopes that to 'this repository.' However, it provides no explicit guidance about when to choose this tool over check_dependency or suggest_alternative.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

suggest_alternativeC

Suggest a lighter, healthier alternative for a package.

ParametersJSON Schema
NameRequiredDescriptionDefault
packageYes

TDQS

C2.7/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description carries the full burden of disclosing behavior. It only states the action and gives no indication of side effects, whether this is read-only, or what the output looks like.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single concise sentence with the action and object front-loaded. The qualifiers 'lighter, healthier' add some vagueness but do not make the description bloated.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no annotations and no output schema, the description leaves the return format, input semantics, and behavioral context mostly unspecified. It is enough to guess the intent, but not sufficient for confident, correct invocation.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters2/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0%, and the description only references 'a package' without clarifying the expected format, allowed values, or examples. It minimally confirms that the package is the input, but does not meaningfully compensate for the missing schema documentation.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('Suggest') and names a clear target ('lighter, healthier alternative for a package'), so the tool's basic purpose is understandable. It does not explicitly differentiate from sibling tools, but the intent is not ambiguous.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no explicit guidance on when to use this tool versus alternatives like check_dependency or get_policy. The only usage signal is implied by the verb 'Suggest,' which is not enough for reliable tool selection.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

TDQS

A3.7/5.0
Disambiguation5/5

Each tool targets a distinct action: evaluating a dependency, suggesting an alternative, and retrieving policy. There is no overlap in purpose, so an agent can easily select the right tool.

Naming Consistency5/5

All tool names follow a consistent verb_noun snake_case pattern (check_dependency, suggest_alternative, get_policy). The naming is predictable and uniform.

Tool Count5/5

With only 3 tools, the set is tightly scoped to the domain of dependency health analysis. Each tool serves a clear, non-redundant purpose and fits within the ideal 3-15 tool range.

Completeness4/5

The tool surface covers checking, suggesting alternatives, and viewing policy, which supports a typical dependency-review workflow. A minor gap is the absence of any policy update or management tool, but this may be intentionally out of scope.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/om-tajne/pkgdiet'

If you have feedback or need assistance with the MCP directory API, please join our Discord server