Skip to main content
Glama

Scan Dependency

scan_dependency
Read-onlyIdempotent

Composite "should I add this npm package to my project" check in ONE call — fans out across deps.dev (license + advisories + version history) and bundlephobia (gzipped/minified bundle size, dependency count, ESM/tree-shake support). Use whenever an agent asks "is X safe / popular / small" or "what does adding lodash cost me". Returns a summary block (is_latest, license, published_at, advisory_count, bundle_kb_min, bundle_kb_gz, dependency_count, has_esm, tree_shakeable), per-advisory detail, links, and a list of recent alternative versions. NPM ecosystem only in v1; PyPI / Maven / Cargo / Go fall under deps.dev:version directly. Partial failures degrade gracefully — bundlephobia's first measurement on a new version can take 5-30s; sources_failed will list it if it times out, the rest still returns.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packageYesnpm package name. Scoped packages (e.g. "@types/node") are accepted.
versionNoSpecific version to check (e.g., "18.3.1"). Defaults to the latest published version when omitted.

Schema Changelog

Changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. First observed

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Describes the fan-out across multiple sources, return structure (summary block, per-advisory detail, links, alternative versions), and graceful degradation when sources fail. This adds substantial behavioral context beyond annotations, which only indicate readOnly, openWorld, idempotent, and non-destructive hints.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is well-structured, front-loading the main purpose and then detailing sources, return values, and edge cases. While slightly verbose, every sentence adds value, and the bullet-like listing aids readability.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Covers return structure in detail (summary block, per-advisory detail, links, alternative versions), ecosystem limitations (NPM only in v1), and partial failure behavior with sources_failed. No output schema exists, so description fully compensates.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% and description adds extra context for both parameters: notes scoped packages accepted for 'package', and default behavior for 'version' (latest). This enhances understanding beyond the schema descriptions.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states it's a composite check for deciding whether to add an npm package, covering license, advisories, version history, and bundle size metrics. It uses a specific verb (scan) and resource (dependency), and distinguishes itself from siblings by explicitly limiting to NPM ecosystem.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides explicit when-to-use criteria ('is X safe / popular / small' or 'what does adding lodash cost me'), notes NPM-only scope in v1, and advises on partial failures and timing (bundlephobia first measurement delay). This gives clear context for selection and expectations.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

B3/5.0
Disambiguation2/5

The tool set mixes four Wikiquote tools with 31 unrelated Pipeworx/Polymarket tools, creating a confusing dual identity. Within the research tooling, ask_pipeworx, ask_pipeworx_beta, and ask_pipeworx_grounded are near-synonyms, and polymarket_arbitrage, polymarket_edges, polymarket_edge_tracker, polymarket_fill_risk overlap heavily, making selection ambiguous.

Naming Consistency3/5

All names are snake_case, but patterns vary: some are verb-first (ask_pipeworx, compare_entities, resolve_entity), some noun-first (entity_profile, polymarket_arbitrage, quote_of_the_day), and several are bare verbs or nouns (search, summary, remember, quotes). Prefix groups like ask_pipeworx* and polymarket_* are consistent, but the overall convention is mixed.

Tool Count2/5

35 tools is excessive for a server named Wikiquote, as only 4 tools (quote_of_the_day, quotes, search, summary) actually serve that domain. The remaining 31 form an unrelated general research and prediction-market toolkit, making the set feel bloated and off-scope for its stated name.

Completeness1/5

As a Wikiquote server, the surface is severely incomplete: there is no random quote, page listing, author/topic browsing, or any write/update operations, and the few quotation tools are buried among unrelated functionality. The unrelated research tools may be internally rich, but they do not address the server's stated purpose.