osv-advisory-mcp-server
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
The record the registry holds
It also ships as a package you run yourself.
{
"server": {
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.cyanheads/osv-advisory-mcp-server",
"description": "Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.",
"repository": {
"url": "https://github.com/cyanheads/osv-advisory-mcp-server",
"source": "github"
},
"version": "0.1.12",
"packages": [
{
"registryType": "npm",
"registryBaseUrl": "https://registry.npmjs.org",
"identifier": "@cyanheads/osv-advisory-mcp-server",
"version": "0.1.12",
"runtimeHint": "bun",
"transport": {
"type": "stdio"
},
"packageArguments": [
{
"value": "run",
"type": "positional"
},
{
"value": "start:stdio",
"type": "positional"
}
],
"environmentVariables": [
{
"description": "HTTP request timeout in milliseconds for OSV.dev API calls.",
"format": "string",
"default": "10000",
"name": "OSV_REQUEST_TIMEOUT_MS"
},
{
"description": "Maximum number of concurrent OSV.dev requests issued by osv_query_batch.",
"format": "string",
"default": "10",
"name": "OSV_BATCH_CONCURRENCY"
},
{
"description": "Maximum number of OSV.dev result pages osv_query_package follows before marking a result truncated.",
"format": "string",
"default": "10",
"name": "OSV_QUERY_MAX_PAGES"
},
{
"description": "Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').",
"format": "string",
"default": "info",
"name": "MCP_LOG_LEVEL"
}
]
},
{
"registryType": "npm",
"registryBaseUrl": "https://registry.npmjs.org",
"identifier": "@cyanheads/osv-advisory-mcp-server",
"version": "0.1.12",
"runtimeHint": "bun",
"transport": {
"type": "streamable-http",
"url": "http://localhost:3010/mcp"
},
"packageArguments": [
{
"value": "run",
"type": "positional"
},
{
"value": "start:http",
"type": "positional"
}
],
"environmentVariables": [
{
"description": "HTTP request timeout in milliseconds for OSV.dev API calls.",
"format": "string",
"default": "10000",
"name": "OSV_REQUEST_TIMEOUT_MS"
},
{
"description": "Maximum number of concurrent OSV.dev requests issued by osv_query_batch.",
"format": "string",
"default": "10",
"name": "OSV_BATCH_CONCURRENCY"
},
{
"description": "Maximum number of OSV.dev result pages osv_query_package follows before marking a result truncated.",
"format": "string",
"default": "10",
"name": "OSV_QUERY_MAX_PAGES"
},
{
"description": "The hostname for the HTTP server.",
"format": "string",
"default": "127.0.0.1",
"name": "MCP_HTTP_HOST"
},
{
"description": "The port to run the HTTP server on.",
"format": "string",
"default": "3010",
"name": "MCP_HTTP_PORT"
},
{
"description": "The endpoint path for the MCP server.",
"format": "string",
"default": "/mcp",
"name": "MCP_HTTP_ENDPOINT_PATH"
},
{
"description": "Authentication mode to use: 'none', 'jwt', or 'oauth'.",
"format": "string",
"default": "none",
"name": "MCP_AUTH_MODE"
},
{
"description": "Sets the minimum log level for output (e.g., 'debug', 'info', 'warn').",
"format": "string",
"default": "info",
"name": "MCP_LOG_LEVEL"
}
]
}
],
"remotes": [
{
"type": "streamable-http",
"url": "https://osv-advisory.caseyjhand.com/mcp"
}
]
},
"_meta": {
"io.modelcontextprotocol.registry/official": {
"status": "active",
"statusChangedAt": "2026-07-11T20:24:11.062494Z",
"publishedAt": "2026-07-11T20:24:11.062494Z",
"updatedAt": "2026-07-11T20:24:11.062494Z",
"isLatest": true
}
}
}
Draft an Agent Plugin from this
An MCP server is raw capability: some tools, wired to something. An Agent Plugin is the packaging that says what job it does, what it leaves behind and where it stops. The prompt below carries this record and asks for the packaging; your own assistant writes it, and nothing here is sent anywhere.
MCP server
These are the publisher's own words, filed by them with the official MCP registry and mirrored here. This catalog did not read them from the publisher and has not run, called or installed anything.
The publisher's own address
https://github.com/cyanheads/osv-advisory-mcp-server
The address the publisher put in their registry record, printed as they wrote it. Nobody here has opened it.