# OSV Scanner

> Use this tool when you need to detect dependency vulnerabilities in your project, as it scans dependencies for known CVEs across multiple ecosystems and prioritizes remediation efforts through static analysis and tiered findings. It takes project dependencies as input and outputs categorized vulnerability findings, including FOUND_IN_SOURCE, UNCERTAIN, and NOT_FOUND_IN_GREP tiers. Ideal for use in development and security testing contexts to identify and address potential security threats.

Canonical page: https://skillsregistry.net/skills/alejandrosaenz117-osv-scanner  
JSON: https://api.skillsregistry.net/v1/skills/alejandrosaenz117-osv-scanner

## Description

Claude Code plugin that integrates Google's OSV Scanner for dependency vulnerability detection. Scans project dependencies for known CVEs across multiple ecosystems including npm, pip, Go, Rust, Maven, and Ruby. Performs grep-based static analysis for reachability triage, categorizing findings into FOUND_IN_SOURCE, UNCERTAIN, and NOT_FOUND_IN_GREP tiers to prioritize remediation efforts.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** media
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/alejandrosaenz117-osv-scanner)
- **Repository:** <https://github.com/alejandrosaenz117/bonfires-marketplace/tree/HEAD/plugins/osv-scanner>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "alejandrosaenz117-osv-scanner"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/alejandrosaenz117-osv-scanner` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/alejandrosaenz117-osv-scanner/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
