Skip to main content
Glama
tedorigawa001

OSV-Scanner-MCP

プロジェクトの依存の脆弱性スキャン(Java / JavaScript / Python / Go)

scan_project

Scans project lockfiles and manifests to detect known dependency vulnerabilities (CVEs/GHSAs) and suggests fixes with coverage details.

Instructions

プロジェクト内のlockfile・マニフェストを検出し、依存ライブラリの既知の脆弱性(CVE/GHSA)をまとめてスキャンする。対応: Java(pom.xml / gradle.lockfile)、JavaScript(package-lock.json / npm-shrinkwrap.json / yarn.lock / pnpm-lock.yaml / bun.lock)、Python(poetry.lock / uv.lock / Pipfile.lock / pdm.lock / requirements.txt)、Go(go.mod)。パッケージマネージャーやビルドは実行しない。応答先頭のcoverageを必ず確認すること: lockfileが無いマニフェスト、バージョン未固定のrequirements行、スキャン対象から外したファイルを示す。各パッケージのdependency_relationは直接依存(direct)か推移的依存(transitive)か(package-lock.json・go.mod・requirements.txtで判定。それ以外はunknown)。coverage.complete=falseの場合は、検出0件でも安全とは判断しないこと。修正版の推奨(suggest_fix)はJava・JavaScript・Python・Goに対応。

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
project_pathYesスキャン対象のプロジェクトディレクトリ、または対応するlockfile・マニフェストの絶対パス

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.7.1

TDQS

A3.7/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations, the description carries the full behavioral burden and does so well: it states that package managers/builds are NOT executed, explains the coverage block (manifests without lockfiles, unpinned requirement lines, excluded files), and defines dependency_relation as direct/transitive/unknown with which files yield which. It omits any note on permissions or runtime cost, keeping it from a 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the core purpose, then proceeds through supported files, behavioral caveats, and the coverage warning in a logical order. It is dense and somewhat long, but each clause adds operational detail rather than filler.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description must explain the return shape, and it does specify the leading coverage object, its false case, and per-package dependency_relation. The picture is largely complete, though the exact findings format and suggest_fix linkage to the separate sibling are left implicit.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100% for the single project_path parameter, and the description adds no new semantics beyond what the schema already states (directory or absolute lockfile/manifest path). Baseline 3 is appropriate when the schema does the heavy lifting.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb+resource (detect lockfiles/manifests and scan dependencies for known CVE/GHSA vulnerabilities) and enumerates the supported ecosystems and exact filenames, which is unusually precise. However, it never distinguishes itself from overlapping siblings like scan_sbom and scan_java_project, which an agent must choose between, so it falls short of a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It implicitly defines when to use it by listing the ecosystems and file types it handles, and it gives a critical caution about coverage.complete=false. But it offers no explicit routing versus scan_sbom, scan_java_project, or scan_java_artifact, so the agent cannot tell when this tool is preferred over those.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.