# Guardian (OSV Security Scanner)

> Use this tool when you need to identify and remediate vulnerabilities in your project dependencies, such as during package installations or CI/CD pipeline runs. Guardian provides automated vulnerability scanning and reporting, integrating with the OSV database to detect potential security threats. It supports multiple package managers and offers configurable severity filtering, making it ideal for security-conscious development workflows.

Canonical page: https://skillsregistry.net/skills/kalvisan-guardian  
JSON: https://api.skillsregistry.net/v1/skills/kalvisan-guardian

## Description

GuardianMCP is a security-focused MCP server built by Kalvisan that provides proactive vulnerability scanning for project dependencies through integration with the OSV (Open Source Vulnerabilities) database. The implementation offers automated vulnerability detection with configurable severity filtering, supports multiple package managers, and includes Docker deployment with multi-stage builds for optimized container size. Built with TypeScript and the MCP SDK, it features npm audit integration, outdated package checking, and structured vulnerability reporting with remediation guidance. Designed for security-conscious development workflows, it enables automated dependency scanning during package installations, before commits, or on explicit security requests, making it valuable for maintaining secure codebases and implementing proactive security monitoring in CI/CD pipelines.

## Trust

- **Trust score (0–1):** 0.92
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/kalvisan-guardian)
- **Repository:** <https://github.com/kalvisan/guardian-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "kalvisan-guardian"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/kalvisan-guardian` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/kalvisan-guardian/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
