Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. Added

TDQS

A4.6/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description discloses significant behavioral traits beyond the annotations: it fans out to external services, can take 5-30s on bundlephobia's first measurement, may time out, and degrades gracefully with sources_failed listing failures. This adds valuable context about latency and failure modes that annotations do not cover.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is dense but well-structured, front-loading the one-call composite check. It uses lists and separators effectively to convey many details without wasted words. It is slightly long, but every sentence earns its place for a tool of this complexity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema, the description compensates by enumerating the returned summary block fields, per-advisory details, links, and alternative versions. It also covers edge cases like partial failures and timeouts, making it highly complete for the tool's purpose.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema already describes both parameters with 100% coverage, including the default behavior for version. The description adds minor context (e.g., scoped packages, NPM-only) but largely relies on the schema. Baseline 3 is appropriate since the schema carries the semantic load.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool is a composite 'should I add this npm package to my project' check that fans out to deps.dev and bundlephobia. It names the source resources and the overall purpose, distinguishing it from unrelated siblings by its focus on npm dependency evaluation.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicitly states 'Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me"', giving direct usage context. It also notes NPM-only in v1 and directs other ecosystems to deps.dev:version, providing a clear alternative.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A3.6/5.0
Disambiguation2/5

Multiple tool clusters are nearly indistinguishable: ask_pipeworx, ask_pipeworx_beta, and ask_pipeworx_grounded overlap heavily (beta is explicitly identical right now), and five polymarket tools (arbitrage, edges, edge_tracker, fill_risk, kalshi_spread) all concern prediction-market edge detection with fuzzy boundaries. entity_profile, recent_changes, and compare_entities also blur together for company research. Only the book tools are cleanly distinct, but they are drowned by the surrounding ambiguity.

Naming Consistency4/5

Most tools follow a consistent snake_case pattern and generally lead with a verb or clear noun (search_books, get_book, subscribe, unsubscribe, validate_claim, resolve_entity). A few depart from the verb-first convention (entity_profile, bet_research, pipeworx_trending, polymarket_edges) but the deviations are minor and do not hinder readability.

Tool Count2/5

35 tools is already heavy, but the critical problem is scope: the server is named gutendex (a book API) yet only 4 of 35 tools relate to books, with the other 31 forming an unrelated Pipeworx data/research/prediction-market suite. The count is inappropriate for the advertised purpose — it feels like two or three separate servers crammed into one.

Completeness2/5

For the gutendex domain, the book tools are thin: search, get, popular, and topic browsing exist, but common Gutendex capabilities like author browsing, language filtering, sorting, and pagination controls are missing. For the actual Pipeworx suite the surface is broad, but the server's stated purpose is gutendex, and the overwhelming majority of tools are completely off-topic, creating a severe coverage mismatch.