# OSV.dev Security Analyzer

> Use this tool when you need to identify and analyze potential vulnerabilities in codebases, and receive security insights and recommendations directly within your workflow. It solves problems related to dependency checking and code security issues, providing outputs such as vulnerability reports and recommendations for remediation. It takes in code files and dependencies as inputs, and integrates with AI tools through the Model Context Protocol.

Canonical page: https://skillsregistry.net/skills/gleicon-osv-security-analyzer  
JSON: https://api.skillsregistry.net/v1/skills/gleicon-osv-security-analyzer

## Description

MCP Security Analyst is a Go-based server that integrates with OSV.dev to identify and analyze potential vulnerabilities in codebases. Developed by gleicon, it provides tools for checking dependencies against known vulnerabilities and analyzing code files for security issues, with optional enhanced static analysis through Semgrep integration. The server communicates through the Model Context Protocol, making it compatible with AI tools like Claude and Cursor IDE, enabling developers to receive security insights and recommendations directly within their workflow.

## Trust

- **Trust score (0–1):** 0.96
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/gleicon-osv-security-analyzer)
- **Repository:** <https://github.com/gleicon/mcp-osv>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "gleicon-osv-security-analyzer"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/gleicon-osv-security-analyzer` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/gleicon-osv-security-analyzer/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
