Mmcp.market

Osv MCP server

by mrfentmen·io.github.mrfentmen/osv-mcp·v1.0.0

Use this MCP server to OSV open source vulnerability data and package security checks. Tools...

A85/100grade A
What users say
No reviews yet
Be the first
Safety scan
A85/100

full report

Adoption
New

0 stars

Reviews

Write one

Nobody has reviewed Osv yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

Osv tools (3)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • check_package

    Check a package and optional version for known open source vulnerabilities.

  • get_vulnerability

    Retrieve one OSV vulnerability by ID, such as GHSA, CVE, or OSV identifier.

  • scan_packages

    Scan several package references in one OSV request. Pass a JSON array of ecosystem, name, and optional version.

Public scan report

scanner v0.1.9 · 2026-09-22 · same rubric, same numbers if you re-run it

no findings
  • Code scan5 source files scanned25/25
  • Live reliabilityno gateway calls yet and no remote to proben/a
  • Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 44 days ago12/15
  • Maintainer identityregistry namespace matches repository owner6/10
Overall 85/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install directly

Runs npx -y osv-mcp on your machine. Read the scan report first; the gateway never runs local packages.

claude mcp add osv-mcp -- npx -y osv-mcp
Add to Cursor

Osv: common questions

Is Osv MCP server safe?
Yes, by our scan: it is graded A (85/100). Read the Osv safety report
How do I install Osv?
It runs on your machine. Copy the Claude Code, Claude Desktop or Cursor config from the install section.
Does Osv need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is Osv maintained?
The last commit was 45 days ago (2026-08-08). The latest release is v1.0.0.
What can I use instead of Osv?
Servers from other publishers that do the same job: Security Intel MCP server, Fedramp Oscal Ssp Lint MCP server and Prodcheck MCP server. Compare all Osv alternatives.

Alternatives to Osv

Same job from other publishers: the closest match first, then the best rated.

All Osv alternatives →
  • Security Intel MCP
    CVE lookups (NVD) and dependency-manifest audits (OSV) for AI agents. No API keys.
    A
  • Fedramp Oscal Ssp Lint
    16 checks on a system-security-plan JSON, in your editor, before a validator returns the package
    A
  • Prodcheck
    4,372 pre-production checks: security, performance, scale, integrations, post-launch.
    A
  • npm Registry MCP Server
    npm registry MCP server — package intelligence, security audits, dependency analysis
    B
  • MCP
    Security tools for your AI: scan, pentest, check headers, guard code and scan repos for secrets.
    A

More from mrfentmen