Skip to main content
Glama

audit

Read-only

Summarize all code checks (dead code, dependencies, security, CVEs, complexity, lint) per stack for a project folder, with severity totals and top findings.

Instructions

Summary of all checks (dead code, dependencies, security, CVEs, complexity, lint) per stack, with totals by severity and the top 5 findings of each engine. Downloads tools on first run.

Args: path: project folder (defaults to the working directory).

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
pathNo.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A3.6/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and destructiveHint=false, but the description adds a genuinely useful trait beyond them: 'Downloads tools on first run', which flags network activity and a first-run side effect (consistent with openWorldHint=true). It also discloses the return shape. It stops short of noting runtime cost or caching behavior.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the result shape, then the notable side effect, then the argument in a compact Args block. Two sentences and an arg line with little waste; only minor redundancy in restating the default already present in the schema.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description usefully characterizes the return value (per-stack summary, severity totals, top 5 findings per engine) and covers the single parameter and first-run download. Adequate for a one-parameter, read-only tool; missing only guidance on cost/runtime and sibling selection.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 0% (the lone parameter has only a title and a default), so the description must compensate, and it does: it explains that 'path' is the project folder and that it defaults to the working directory. It does not clarify relative-vs-absolute path handling, but the semantic gap is largely closed.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description names a concrete operation and enumerates exactly what it aggregates (dead code, dependencies, security, CVEs, complexity, lint) and the shape of the result (totals by severity, top 5 findings per engine). It does not, however, distinguish itself from the sibling 'check', so an agent cannot tell from the text alone whether this is the aggregate run or the individual check.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

There is no explicit when-to-use, when-not-to-use, or routing statement relative to the sibling 'check'. The only usage hint is the path default, which is about invocation, not selection. The agent must infer that this is the umbrella/summary tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools