# OSV Database API

> Use this tool when you need to assess the security posture of software dependencies by querying for security vulnerabilities in specific packages. The OSV Database API solves problems related to manual vulnerability searches, providing outputs such as CVE information, affected versions, and fixed versions for given packages. It is particularly useful for developers and security professionals who require efficient vulnerability assessment and management.

Canonical page: https://skillsregistry.net/skills/osv-database  
JSON: https://api.skillsregistry.net/v1/skills/osv-database

## Description

OSV-MCP is a lightweight server implementation that integrates with the OSV Database API, allowing AI assistants to query for security vulnerabilities in software packages. Developed by Eden Yavin, it provides tools for retrieving CVE information related to specific packages, identifying affected versions, and determining which versions contain fixes for known vulnerabilities. The server runs using the Model Context Protocol and is particularly useful for developers and security professionals who need to assess the security posture of their dependencies without manually searching through vulnerability databases.

## Trust

- **Trust score (0–1):** 0.99
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/osv-database)
- **Repository:** <https://github.com/edenyavin/osv-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "osv-database"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/osv-database` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/osv-database/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
