osv-advisory-mcp-server
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
https://osv-advisory.caseyjhand.com/mcpCurrent observation
This endpoint answered at its latest recorded check.
What this server reports about itself
Self-reported at initialize. Not verified by Licium.
- Server name
- osv-advisory-mcp-server
- Version
- 0.1.12
- Capability keys
- logging, resources, tools, prompts
- Tool names
- osv_list_ecosystems, osv_query_package, osv_get_vulnerability, osv_query_batch
This server provides read-only access to the OSV.dev vulnerability database. - Use osv_list_ecosystems to discover valid ecosystem identifier strings before querying. - Use osv_query_package to check if a single package version is vulnerable. - Use osv_query_batch for dependency audits — pass a full lockfile as {name, ecosystem, version} tuples. - Use osv_get_vulnerability for the full advisory record when osv_query_package returns a vuln ID. - OSV results include aliases (CVE IDs) — chain these to nist-nvd-mcp-server for CVSS scoring, EPSS, and CISA KEV status. - No API key required. No rate limit published — prefer batch queries over repeated single queries.
Reported Aug 17, 2026, 05:06 AM UTC.
Check history
Oldest to newest. Each row is one recorded check.
- respondsMCP initialize · 8s limit · HTTP 200 · 134ms
- respondsMCP initialize · 8s limit · HTTP 200 · 355ms
- respondsMCP initialize · 8s limit · HTTP 200 · 246ms
- respondsMCP initialize · 8s limit · HTTP 200 · 347ms