Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. Added

TDQS

A4.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnly, openWorld, idempotent, and non-destructive. The description adds valuable runtime behavior: partial failures degrade gracefully, bundlephobia's first measurement can take 5-30s, and sources_failed will list if it times out. This goes beyond annotations, though it doesn't cover every possible edge (e.g., rate limits), which is acceptable.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

A dense paragraph but every sentence contributes: purpose, use case, return fields, ecosystem scope, and failure behavior. Slightly long for a tool description, but justified given the composite nature and multiple data sources. No wasted words.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, so the description correctly documents the return shape, including the summary block fields, per-advisory details, links, and alternative versions. It also covers edge cases like timeouts, partial failures, and ecosystem limitations. Complete for a complex composite tool.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema covers both parameters with descriptions (100% coverage), including scoped package acceptance and defaulting behavior. The description doesn't add new parameter-level details beyond the schema, but it does frame the parameters within the composite use case. Baseline 3 is appropriate since the schema already handles the burden.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly identifies this as a composite npm-package evaluation tool, with specific verbs like 'check' and 'fans out', and a concrete use case ('should I add this npm package'). It distinguishes itself from sibling tools by explicitly scoping to NPM and naming deps.dev:version as the alternative for other ecosystems.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides explicit when-to-use guidance with concrete examples ('is X safe / popular / small', 'what does adding lodash cost me'), and an explicit alternative: 'PyPI / Maven / Cargo / Go fall under deps.dev:version directly'. Also clearly notes the NPM-only scope in v1.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.8/5.0
Disambiguation2/5

Several tools occupy blurred boundaries: ask_pipeworx, ask_pipeworx_beta, ask_pipeworx_grounded, deep_research, and validate_claim all route questions to overlapping data pipelines, and the Polymarket family (bet_research, polymarket_edges, polymarket_arbitrage, polymarket_fill_risk, polymarket_kalshi_spread) heavily overlaps in purpose. Individual descriptions are detailed, but an agent must read long text to avoid misselection, especially when the three anime-quote tools are surrounded by unrelated tool families.

Naming Consistency3/5

Most tools use snake_case and many begin with verbs (ask_, search_, resolve_, scan_, compare_, validate_), but several are noun-first or noun-phrase names like entity_profile, bet_research, random_quote, recent_alerts, recent_changes, and pipeworx_trending. There is no chaotic camelCase/snake_case mix, but the convention is not applied consistently enough for a predictable pattern.

Tool Count2/5

34 tools is heavy for any single-purpose server, and the vast majority have nothing to do with anime quotes—they are Pipeworx data tools, prediction-market tools, subscription tools, memory tools, and AI-audit tools. For a server named animequotes, only random_quote, search_by_anime, and search_by_character fit the stated purpose, making the count wildly disproportionate.

Completeness3/5

For the apparent anime-quote domain, random_quote, search_by_anime, and search_by_character cover basic lookup but leave notable gaps: no search by quote text, no quote-by-id fetch, no ability to list all series or characters, and no pagination or metadata browsing. The unrelated tools do not fill these gaps, so the anime-quote surface is functional but incomplete.