MCP bundle: stateless agent-facing build sanity checks. Three tools sharing one Worker and one cache. Tools: check_model_currency (provider model deprecation lookup), check_dep_health (package supply-chain composite), check_runtime_eol (language/framework/distro EOL). Each response carries {as_of, sources[]} for auditable freshness.
Three well-defined tools with complete input schemas, strong descriptions (194 - 250 chars), and clear enum constraints. All parameters are typed and described. Tool names follow verb_noun pattern (check_*). Descriptions explain WHAT, WHEN, and WHY with auditable provenance. Output structure documented (mode parameter with three options). No security issues detected (read-only tools, no secrets in params). Main gaps: no output schema formally documented in code; error handling guidance minimal; no tool annotations (readOnlyHint present conceptually but not in schema); composition is single-purpose (good) but no batch variants offered.
Audit a package's supply-chain health in one call: latest stable version, target-version freshness, deduplicated security advisories (CVE/GHSA via OSV.dev, sorted by severity), licenses, release cadence, and risk flags. Stitches deps.dev (Google's package-graph API) + OSV.dev (free unlimited CVE feed) + ecosystem registries. Saves ~5,000 tokens per call vs the calling model fetching and reasoning through deps.dev + npm/PyPI/Cargo registry + GitHub advisory pages separately. Invoke before any `npm install` / `pip install` / `cargo add` / `go get` an agent is about to recommend or run. Default mode 'concise' (verdict + key facts only); 'json' for full structured response; 'pretty' for human / generative-UI rendering. Response includes auditable {as_of, sources[]}.
Check whether an LLM model ID is still callable. Returns deprecation status (active / deprecated / shutdown), days until shutdown, and replacement-model suggestions, sourced from deprecations.info's tracked feed of OpenAI / Anthropic / Google / Vertex / Cohere / Bedrock model lifecycle events. Saves ~3,000 tokens per call vs the calling model reading provider deprecation pages. Invoke before writing any code that instantiates an SDK with a hard-coded model string — training data is months stale and providers shut down models constantly. Default mode is 'concise' (verdict + key facts only); pass mode='json' for the full structured response or mode='pretty' for human / generative-UI rendering. Response includes auditable {as_of, sources[]}.
Check end-of-life status for a runtime / framework / OS / database / programming language. Returns active support status, security-only window, EOL date, days until EOL, and the currently recommended LTS target. For fully-retired products (CentOS, Windows 7, etc.) returns curated successor product names. Sources endoflife.date (455+ tracked products). Saves ~2,000 tokens per call vs the calling model reading per-product EOL pages. Invoke when writing Dockerfile FROM lines, CI matrix configs, `engines` fields in package.json, or any deployment decision touching a versioned runtime. Default mode 'concise'; 'json' for full cycle matrix; 'pretty' for human / generative-UI rendering. Response includes auditable {as_of, sources[]}.
Output schema not formally documented in code. Descriptions mention response structure ({as_of, sources[]}) but no JSON Schema definition visible for return types. LLMs cannot plan downstream operations without knowing exact output fields.
Error handling lacks recovery guidance. Tool error responses return generic '-32000' code with message string. No categorization (retryable vs user-fixable vs fatal) or actionable next steps for LLM.
Tool annotations missing from schema. All three tools are read-only (no side effects), but inputSchema lacks readOnlyHint annotation. This forces LLMs to infer safety from descriptions rather than machine-readable metadata.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | A | 84 | 2026-07-28+ | v2 |
No batch variants. Agents checking multiple models/packages/runtimes must call tools sequentially. Offering batch parameters (model_ids[], packages[]) would reduce token cost and latency.