Osv is answering right now. Last checked 14 min ago. It exposes 35 tools. Last commit 13 Sep 2026.
OSV.dev (Open Source Vulnerabilities) MCP.
Every tool that appeared, vanished or quietly changed what it asks for. Recorded since 8 August 2026. No other catalogue keeps this.
Today is the operative word: we check Osv every 15 minutes and re-read its code on every release. Watch it and you find out the day that stops being true.
Endpoint below is the one we actually reach during checks — not the one copied from a README. Last verified 14 min ago.
claude mcp add osv --transport http https://gateway.pipeworx.io/osv/mcp
{
"mcpServers": {
"osv": {
"url": "https://gateway.pipeworx.io/osv/mcp"
}
}
}
[mcp_servers.osv]
url = "https://gateway.pipeworx.io/osv/mcp"
{
"mcpServers": {
"osv": {
"url": "https://gateway.pipeworx.io/osv/mcp"
}
}
}
{
"mcpServers": {
"osv": {
"url": "https://gateway.pipeworx.io/osv/mcp"
}
}
}
Read directly from the server with tools/list, grouped by what they act on.
If a tool disappears, we record the date.
polymarket_arbitrage
polymarket_edge_tracker
polymarket_edges
polymarket_fill_risk
polymarket_kalshi_spread
ask_pipeworx
ask_pipeworx_beta
ask_pipeworx_grounded
pipeworx_feedback
pipeworx_trending
recent_alerts
recent_changes
scan_competitor_ai_presence
scan_dependency
query_batch
bet_research
query_by_commit
compare_entities
deep_research
discover_tools
entity_profile
forget
generate_llms_txt
query_package_vulns
recall
remember
resolve_entity
subscribe
list_subscriptions
suggest_questions
unsubscribe
validate_claim
ai_visibility_check
get_vulnerability
search_within
| URL | Transport | State | Latency | Checked |
|---|---|---|---|---|
| https://gateway.pipeworx.io/osv/mcp | streamable-http | answering | 108 ms | 14 min ago |
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Search public open-source code, documentation, metadata, vulnerabilities, changelogs, and examples.
npm MCP — search packages, bundle sizes, vulnerabilities, compare downloads.
CISA Known Exploited Vulnerabilities catalog
Real, live npm/PyPI docs and OSV.dev vulnerability data for AI coding agents. No fake data.
Vanta compliance MCP server: vulnerabilities, tests, controls, evidence, people, vendors, docs
Analyzes code for bugs, security vulnerabilities, and code smells
MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.
Answers built from our own checks of this server.