Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
LICENSE_SENTINEL_SCAN_CURRENT_ENVNoSet to '1' to include the current environment running the server in the dependency scan. By default, the server's own packages are never scanned.0

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
audit_projectA

Scan a project's dependencies and report licensing risk.

Args: path: Project directory to scan. Defaults to the current directory. context: How you distribute your product. One of proprietary (closed-source product you distribute), saas-backend (you only run it, never distribute), permissive (your own project is MIT/Apache/BSD), copyleft-ok (your own project is GPL family).

Returns: Counts per verdict plus every BLOCK and REVIEW item with the reason.

check_packageA

Check packages or raw license strings before installing them.

Args: names: Package or license strings to check. Accepts the messy real-world forms: AGPL-3.0, BUSL-1.1, GPLv3, Apache License 2.0, MIT OR Apache-2.0, or a comma-separated string of any of these. These are license strings, not package lookups: to audit what is actually installed in a project directory, use audit_project. context: Distribution context, see audit_project.

Returns: One line per input with its verdict and the reason.

generate_noticesA

Write a THIRD-PARTY-NOTICES.md attribution document for client hand-off.

Args: path: Project directory to scan. output: Output file. Relative paths are resolved against path.

Returns: The absolute path written and how many dependencies were listed.

Prompts

Interactive templates invoked by user choice

NameDescription
pre_release_license_reviewPrompt: chain a dependency audit into a go/no-go release review.

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A4.2/5.0

Scored across 3 tools

Disambiguation5/5

Each tool targets a distinct stage: audit_project scans an existing project, check_package evaluates individual license strings or packages before install, and generate_notices produces an attribution file. The descriptions explicitly clarify the boundary between audit_project and check_package, so an agent is unlikely to select the wrong tool.

Naming Consistency5/5

All three tools follow the same verb_noun snake_case pattern: audit_project, check_package, generate_notices. The naming is predictable and immediately conveys the action and target of each tool.

Tool Count5/5

Three tools is a well-scoped count for a focused license-compliance server. Each tool covers a non-overlapping, meaningful workflow step without unnecessary bloat or missing core functionality.

Completeness4/5

The toolset covers the main license compliance lifecycle: audit a project, check new dependencies, and generate notices. Minor gaps exist around policy configuration/allowlisting and detailed reporting on all permissive dependencies, but agents can work around these using the provided outputs.

Maintenance

ActivityMaintained
ResponsivenessNo issues