OSV Vulnerability Database
The OSV MCP server provides AI assistants with access to the Open Source Vulnerabilities (OSV) database through a standardized interface. Built by StacklokLabs, this implementation exposes three primary tools: querying vulnerabilities for specific package versions or commits, batch querying for multiple packages simultaneously, and retrieving detailed information about specific vulnerabilities by ID. The server is written in Go using the mark3labs/mcp-go library and includes comprehensive CI/CD workflows for building, testing, and security scanning. It's particularly valuable for developers and security professionals who need to integrate vulnerability checking into their AI-assisted workflows for software composition analysis and security auditing.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately.
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- database
- Source
- PulseMCP
- Repository
- github.com/stackloklabs/osv-mcp
- Author type
- human
- Updated
- 2026-04-25
Use via MCP
Resolve OSV Vulnerability Database from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.