Osv MCP server
Use this MCP server to OSV open source vulnerability data and package security checks. Tools...
0 stars
Reviews
Write oneNobody has reviewed Osv yet.
If you have run it, two minutes of your experience saves the next person an afternoon.
Osv tools (3)
write = sends, deletes, buys or postsRead from the package source without running it. The installed server may list more.
check_packageCheck a package and optional version for known open source vulnerabilities.
get_vulnerabilityRetrieve one OSV vulnerability by ID, such as GHSA, CVE, or OSV identifier.
scan_packagesScan several package references in one OSV request. Pass a JSON array of ecosystem, name, and optional version.
Public scan report
scanner v0.1.9 · 2026-09-22 · same rubric, same numbers if you re-run it
- Code scan5 source files scanned25/25
- –Live reliabilityno gateway calls yet and no remote to proben/a
- –Tool poisoningtools not inspected (local package is not executed); not countedn/a
- Auth qualitylocal package, no credentials required12/15
- Maintenancelast push 44 days ago12/15
- Maintainer identityregistry namespace matches repository owner6/10
Install directly
Runs npx -y osv-mcp on your machine. Read the scan report first; the gateway never runs local packages.
claude mcp add osv-mcp -- npx -y osv-mcp
Osv: common questions
- Is Osv MCP server safe?
- Yes, by our scan: it is graded A (85/100). Read the Osv safety report
- How do I install Osv?
- It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
- Does Osv need an API key?
- Not as far as the registry entry and our scan can tell: no credentials are declared or required.
- Is Osv maintained?
- The last commit was 45 days ago (2026-08-08). The latest release is v1.0.0.
- What can I use instead of Osv?
- Servers from other publishers that do the same job: Security Intel MCP server, Fedramp Oscal Ssp Lint MCP server and Prodcheck MCP server. Compare all Osv alternatives.
Alternatives to Osv
Same job from other publishers: the closest match first, then the best rated.
- Security Intel MCPCVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.not reviewedNewA
- Fedramp Oscal Ssp Lint16 checks on a system-security-plan JSON, in your editor, before a validator returns the packagenot reviewedNewA
- Prodcheck4,372 pre-production checks: security, performance, scale, integrations, post-launch.not reviewedGrowingA
- npm Registry MCP Servernpm registry MCP server — package intelligence, security audits, dependency analysisnot reviewedGrowingB
- MCPSecurity tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.not reviewedGrowingA