# OSV Vulnerability Database

> Use this tool when you need to integrate vulnerability checking into your AI-assisted workflows for software composition analysis and security auditing. It provides access to the Open Source Vulnerabilities (OSV) database, allowing you to query vulnerabilities by package version, commit, or ID, and retrieve detailed information about specific vulnerabilities. This tool is ideal for developers and security professionals who require standardized and automated vulnerability scanning in their workflows.

Canonical page: https://skillsregistry.net/skills/stackloklabs-osv  
JSON: https://api.skillsregistry.net/v1/skills/stackloklabs-osv

## Description

The OSV MCP server provides AI assistants with access to the Open Source Vulnerabilities (OSV) database through a standardized interface. Built by StacklokLabs, this implementation exposes three primary tools: querying vulnerabilities for specific package versions or commits, batch querying for multiple packages simultaneously, and retrieving detailed information about specific vulnerabilities by ID. The server is written in Go using the mark3labs/mcp-go library and includes comprehensive CI/CD workflows for building, testing, and security scanning. It's particularly valuable for developers and security professionals who need to integrate vulnerability checking into their AI-assisted workflows for software composition analysis and security auditing.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/stackloklabs-osv)
- **Repository:** <https://github.com/stackloklabs/osv-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "stackloklabs-osv"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/stackloklabs-osv` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/stackloklabs-osv/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
