Guardian (OSV Security Scanner)
GuardianMCP is a security-focused MCP server built by Kalvisan that provides proactive vulnerability scanning for project dependencies through integration with the OSV (Open Source Vulnerabilities) database. The implementation offers automated vulnerability detection with configurable severity filtering, supports multiple package managers, and includes Docker deployment with multi-stage builds for optimized container size. Built with TypeScript and the MCP SDK, it features npm audit integration, outdated package checking, and structured vulnerability reporting with remediation guidance. Designed for security-conscious development workflows, it enables automated dependency scanning during package installations, before commits, or on explicit security requests, making it valuable for maintaining secure codebases and implementing proactive security monitoring in CI/CD pipelines.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-28.
Scan details: Circle-IR · 2026-09-28 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- database
- Source
- PulseMCP
- Repository
- github.com/kalvisan/guardian-mcp
- Author type
- human
- Last scanned
- 2026-09-28
- Updated
- 2026-09-28
Use via MCP
Resolve Guardian (OSV Security Scanner) from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.