Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. First observed

TDQS

A4.9/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses concrete behavioral traits beyond annotations: 'bundlephobia's first measurement on a new version can take 5-30s' and 'Partial failures degrade gracefully — sources_failed will list it if it times out, the rest still returns'. These latency and failure handling details are not present in the annotations, which already declare the operation read-only and idempotent. No contradiction with annotations exists.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is six sentences long, each serving a distinct purpose: defining the composite operation, listing covered data sources, giving usage triggers, enumerating return fields, declaring ecosystem scope, and explaining failure behavior. Every sentence earns its place, and the main purpose is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the tool's complexity (composite of two external services, no output schema), the description compensates fully by enumerating every returned field in the summary block, detailing partial failure and timeout behavior, and stating ecosystem limitations. An agent can correctly invoke the tool and interpret results without needing additional context.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with descriptions for both parameters, giving a baseline of 3. The description adds useful semantics: 'Scoped packages (e.g. "@types/node") are accepted' and 'Defaults to the latest published version when omitted', which clarify invocation specifics not fully captured in the schema. This meaningful addition justifies a score above baseline, though it is not extensive enough for 5.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with 'Composite should I add this npm package to my project check in ONE call', which precisely states the tool's purpose, resource, and composite nature. It distinguishes itself from siblings by explicitly limiting scope to the NPM ecosystem and naming the backend services (deps.dev and bundlephobia), which no other sibling tool appears to combine.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

It explicitly says 'Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me"', giving clear invocation triggers. It also provides a direct exclusion: 'PyPI / Maven / Cargo / Go fall under deps.dev:version directly', pointing to an alternative for non-NPM packages.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.9/5.0
Disambiguation2/5

Several tool clusters have genuinely fuzzy boundaries: ask_pipeworx, ask_pipeworx_beta, ask_pipeworx_grouned, and deep_research all route to the same 5,767 tools and differ only by use-case nuance, while polymarket_edges, polymarket_arbitrage, and bet_research all surface trading opportunities. scan_competitor_ai_presence is a thin wrapper over ai_visibility_check, and entity_profile, recent_changes, and compare_entities pull overlapping company data. The descriptions are detailed, but an agent can easily select the wrong tool in these clusters.

Naming Consistency4/5

All tools use snake_case and family prefixes are consistent (polymarket_*, pipeworx, datalastic_*, scan_*, ask_*), making the set predictable and readable. The main deviation is verb placement — verb-first (list_subscriptions, resolve_entity, search_within) vs noun-first (entiy_profile, recent_alerts, bet_research) — and prefix position varies between ask_pipeworx and pipeworx_feedback, but these are minor.

Tool Count2/5

33 tools exceeds the heavy threshold, and the count is padded by redundancy: four ask_pipeworx variants that are near-identical, six polymarket tools with overlapping scans, and wrapper tools like scan_competitor_ai_presence that just call ai_visibility_check. The server name suggests maritime focus but only two tools serve that domain, while the rest span a sprawling data-research, prediction-market, AI-visibility, and npm-scanning surface. Consolidating the ask_pipeworx family into one router with a mode parameter and merging wrappers would trim the set to roughly 20 tools without losing capability.

Completeness4/5

The core data-research lifecycle is thoroughly covered: resolve_entity feeds entity_profile, compare_entities, recent_changes, validate_claim, and deep_research, and the prediction-market workflow includes discovery, edge detection, fill-risk validation, and cross-venue analysis. Subscriptions, memory, and feedback are well supported. Minor gaps exist — the datalastic maritime piece has only live position lookups (no history or fleet tools), and one-offs like generate_llms_txt and scan_dependency feel unrelated — but there are no critical dead ends.