OSV Database API
OSV-MCP is a lightweight server implementation that integrates with the OSV Database API, allowing AI assistants to query for security vulnerabilities in software packages. Developed by Eden Yavin, it provides tools for retrieving CVE information related to specific packages, identifying affected versions, and determining which versions contain fixes for known vulnerabilities. The server runs using the Model Context Protocol and is particularly useful for developers and security professionals who need to assess the security posture of their dependencies without manually searching through vulnerability databases.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-19.
Scan details: Circle-IR · 2026-09-19 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- database
- Source
- PulseMCP
- Repository
- github.com/edenyavin/osv-mcp
- Author type
- human
- Last scanned
- 2026-09-19
- Updated
- 2026-09-19
Use via MCP
Resolve OSV Database API from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.