Osv Advisory MCP Server is answering right now. Last checked 13 min ago. 101 installs a week from npm. It exposes 4 tools. Last commit 25 Aug 2026.
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 25 August 2026. No other catalogue keeps this.
Today is the operative word: we check Osv Advisory MCP Server every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 13 min ago.
claude mcp add osv-advisory-mcp-server --transport http https://osv-advisory.caseyjhand.com/mcp
{
"mcpServers": {
"osv-advisory-mcp-server": {
"url": "https://osv-advisory.caseyjhand.com/mcp"
}
}
}
[mcp_servers.osv-advisory-mcp-server]
url = "https://osv-advisory.caseyjhand.com/mcp"
{
"mcpServers": {
"osv-advisory-mcp-server": {
"url": "https://osv-advisory.caseyjhand.com/mcp"
}
}
}
{
"mcpServers": {
"osv-advisory-mcp-server": {
"url": "https://osv-advisory.caseyjhand.com/mcp"
}
}
}
This one needs environment variables set before it will start:
OSV_REQUEST_TIMEOUT_MS (HTTP request timeout in milliseconds for OSV.dev API calls.), OSV_BATCH_CONCURRENCY (Maximum number of concurrent OSV.dev requests issued by osv_query_batch.), OSV_QUERY_MAX_PAGES (Maximum number of OSV.dev result pages osv_query_package follows before marking a result truncated.), MCP_HTTP_HOST (The hostname for the HTTP server.), MCP_HTTP_PORT (The port to run the HTTP server on.), MCP_HTTP_ENDPOINT_PATH (The endpoint path for the MCP server.), MCP_AUTH_MODE (Authentication mode to use: 'none', 'jwt', or 'oauth'.), MCP_SESSION_MODE (HTTP session mode. This server deploys stateless because its tools do not use multi-round input.), MCP_LOG_LEVEL (Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').).
The author declared them in the registry entry; get the values from the project itself.
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
osv_get_vulnerability
osv_list_ecosystems
osv_query_batch
osv_query_package
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://osv-advisory.caseyjhand.com/mcp | streamable-http | answering | 391 ms | 13 min ago |
OSV.dev (Open Source Vulnerabilities) MCP.
Secret, CVE and dependency-vulnerability scanning for AI agents (free, OSV.dev).
Dependency vulns & malicious-package advisories. Register in-session — free testnet funds.
Real-time Python package and vulnerability data for AI coding agents.
Real, live npm/PyPI docs and OSV.dev vulnerability data for AI coding agents. No fake data.
MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.
FinishKit MCP: scan GitHub repos for security vulnerabilities, deployment blockers, and quality
CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
Answers built from our own checks of this server.