# Kodus OSV

> Use this tool when you need to identify open source vulnerabilities in your codebase, as it provides an HTTP server for querying OSV (Open Source Vulnerability) data via osv_query and osv_query_batch tools, accepting git repository inputs and returning vulnerability reports as output. This tool solves problems related to security auditing and compliance, enabling developers to detect and mitigate vulnerabilities in their open source dependencies. It is ideal for use cases involving automated vulnerability scanning and continuous integration pipelines.

Canonical page: https://skillsregistry.net/skills/kodustech-kodus-osv  
JSON: https://api.skillsregistry.net/v1/skills/kodustech-kodus-osv

## Description

HTTP server exposing OSV (v1) for open source vulnerability lookup via osv_query/osv_query_batch tools.

## Trust

- **Trust score (0–1):** 0.99
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Category:** security
- **Updated:** 2026-09-28

## Source

- **Source listing:** [Smithery](https://smithery.ai/server/kodustech/kodus-osv)
- **Repository:** <https://github.com/kodustech/mcp-osv>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "kodustech-kodus-osv"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/kodustech-kodus-osv` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/kodustech-kodus-osv/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
