osv-advisory-mcp-server

Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.

¿Debería usar esto?

Calidad y seguridad

A
Calidad de la descripción
100%
Integridad del esquema
83%
Calidad de los nombres
80%
Riesgo de envenenamiento
100%
Coincidencia de permisos
100%
Cumplimiento del protocolo
100%

Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.

Costo de contexto

~5,898Tokens (definiciones de herramientas)
~17.6 KBTamaño de respuesta típico
Impacto significativo en la atención (4.61% del contexto de 128k)

Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.

Instalar

Instalación con un clic

Agrega esto a tu archivo `claude_desktop_config.json`:

{
  "mcpServers": {
    "osv-advisory-mcp-server": {
      "command": "bun",
      "args": [
        "@cyanheads/osv-advisory-mcp-server"
      ]
    }
  }
}

Paquetes ejecutables

npm@cyanheads/osv-advisory-mcp-server0.1.15streamable-http

Puntos de conexión remotos

https://osv-advisory.caseyjhand.com/mcpstreamable-http

Qué puede hacer

Inventario de herramientas

Herramientas (4)

🟢 Solo lectura🟡 Escritura🔴 Eliminación⚪ Desconocido
🟢osv_list_ecosystems

Return the supported ecosystem identifier strings for osv_query_package and osv_query_batch: every ecosystem the OSV schema names that OSV.dev accepts at query time, plus GIT, as verified on 2026-09-24. Ecosystem strings are case-sensitive exact matches — passing "pypi" instead of "PyPI" returns an error from the API. Use this tool to discover valid ecosystem strings before querying, or to verify an ecosystem identifier from a lockfile format. The list is static and may lag ecosystems added after that date.

Esquema de entrada

{
  "type": "object",
  "properties": {},
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "ecosystems": {
      "type": "array",
      "items": {
        "type": "string",
        "description": "A supported ecosystem identifier string."
      },
      "description": "Supported ecosystem identifier strings. These are case-sensitive exact matches required by the ecosystem parameter of osv_query_package and osv_query_batch."
    },
    "note": {
      "type": "string",
      "description": "Advisory note about list currency and canonical source."
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode."
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "ecosystems",
        "note"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢osv_query_package(name, ecosystem, version)

Query known vulnerabilities for a single package version across any supported ecosystem. Returns all matching OSV advisories with severity (CVSS vectors), CVE aliases, affected version ranges, and the fixed versions listed for the queried package. Use osv_list_ecosystems to validate the ecosystem string before querying — ecosystem strings are case-sensitive exact matches and an invalid value returns an error, not empty results.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "name": {
      "type": "string",
      "pattern": "\\S",
      "description": "Package name as it appears in the ecosystem (e.g. \"express\", \"requests\", \"serde\"). Case-sensitive."
    },
    "ecosystem": {
      "type": "string",
      "pattern": "\\S",
      "description": "Ecosystem identifier. Must be an exact match (case-sensitive). Use osv_list_ecosystems to see valid values. Examples: \"npm\", \"PyPI\", \"crates.io\", \"Go\", \"Maven\", \"NuGet\"."
    },
    "version": {
      "type": "string",
      "pattern": "\\S",
      "description": "Package version to check (e.g. \"4.17.1\", \"3.1.4\", \"1.0.0\"). Must be an exact version string, not a range."
    }
  },
  "required": [
    "name",
    "ecosystem",
    "version"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "vulns": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "id": {
            "type": "string",
            "description": "OSV vulnerability ID (e.g. \"GHSA-29mw-wpgm-hmr9\", \"PYSEC-2024-1\"). Pass to osv_get_vulnerability to retrieve the full advisory record."
          },
          "summary": {
            "type": "string",
            "description": "One-line vulnerability description."
          },
          "aliases": {
            "type": "array",
            "items": {
              "type": "string",
              "description": "A CVE ID or other alias."
            },
            "description": "Alternative IDs — typically CVE IDs (e.g. [\"CVE-2020-28500\"]). Accepted by nist-nvd-mcp-server for CVSS scores, EPSS, and CISA KEV status."
          },
          "severity": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "type": {
                  "type": "string",
                  "description": "Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\"."
                },
                "score": {
                  "type": "string",
                  "description": "CVSS vector string (e.g. \"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L\"), or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\"."
                }
              },
              "required": [
                "type",
                "score"
              ],
              "additionalProperties": false,
              "description": "One record-level severity entry."
            },
            "description": "Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for advisories not yet scored and for advisories that score each affected package separately — severitySource then carries the queried package entry used."
          },
          "severityLabel": {
            "description": "Severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses the queried package's affected-level severity entries when the record-level list is empty. Null when no source yields a label.",
            "type": [
              "string",
              "null"
            ]
          },
          "severitySource": {
            "anyOf": [
              {
                "type": "object",
                "properties": {
                  "type": {
                    "type": "string",
                    "enum": [
                      "database_specific",
                      "Ubuntu",
                      "CVSS_V3",
                      "CVSS_V4"
                    ],
                    "description": "Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector."
                  },
                  "score": {
                    "type": "string",
                    "description": "The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector."
                  },
                  "computedScore": {
                    "description": "CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.",
                    "type": "number"
                  }
                },
                "required": [
                  "type",
                  "score"
                ],
                "additionalProperties": false
              },
              {
                "type": "null"
              }
            ],
            "description": "The severity entry severityLabel was derived from. Null exactly when the label is."
          },
          "fixedVersions": {
            "type": "array",
            "items": {
              "type": "string",
              "description": "A version that fixes the vulnerability for the queried package."
            },
            "description": "Every fixed version the advisory lists for the queried package, in record order. A multi-interval range contributes one per interval (typically one per release line); affectedRanges shows which interval each one closes. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package."
          },
          "affectedRanges": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "packageName": {
                  "type": "string",
                  "description": "Affected package name (may differ from queried name for umbrella advisories). Empty for source-only advisory ranges."
                },
                "ecosystem": {
                  "type": "string",
                  "description": "Affected package ecosystem. Empty for source-only advisory ranges."
                },
                "rangeType": {
                  "type": "string",
                  "description": "\"SEMVER\", \"ECOSYSTEM\", or \"GIT\"."
                },
                "repo": {
                  "description": "Source repository URL for GIT ranges. Absent on version ranges.",
                  "type": "string"
                },
                "introduced": {
                  "description": "First affected version (convenience view — see events[]).",
                  "type": "string"
                },
                "fixed": {
                  "description": "The last \"fixed\" event of this range (convenience view — a multi-interval range carries several; see events[]).",
                  "type": "string"
                },
                "lastAffected": {
                  "description": "Last affected version. Present when no fix exists (convenience view — see events[]).",
                  "type": "string"
                },
                "events": {
                  "description": "Ordered event boundaries for this range — the loss-free view preserving multiple introduced/fixed pairs the scalar fields collapse.",
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "type": {
                        "type": "string",
                        "description": "Event boundary type: \"introduced\", \"fixed\", \"last_affected\", or \"limit\"."
                      },
                      "value": {
                        "type": "string",
                        "description": "Version string or commit identifier at this boundary."
                      }
                    },
                    "required": [
                      "type",
                      "value"
                    ],
                    "additionalProperties": false,
                    "description": "One ordered range event."
                  }
                },
                "versions": {
                  "description": "Explicit affected versions listed on this package entry. Absent or empty when affected versions are expressed only as ranges.",
                  "type": "array",
                  "items": {
                    "type": "string",
                    "description": "An explicitly-listed affected version."
                  }
                }
              },
              "required": [
                "packageName",
                "ecosystem",
                "rangeType"
              ],
              "additionalProperties": false,
              "description": "One affected version range."
            },
            "description": "Version ranges affected by this vulnerability."
          },
          "cweIds": {
            "type": "array",
            "items": {
              "type": "string",
              "description": "A CWE ID string."
            },
            "description": "CWE weakness IDs (e.g. [\"CWE-79\", \"CWE-94\"]). Populated on GHSA-sourced records; empty otherwise."
          },
          "published": {
            "type": "string",
            "description": "ISO 8601 timestamp when the advisory was published."
          },
          "modified": {
            "type": "string",
            "description": "ISO 8601 timestamp of last modification."
          }
        },
        "required": [
          "id",
          "summary",
          "aliases",
          "severity",
          "severityLabel",
          "severitySource",
          "fixedVersions",
          "affectedRanges",
          "cweIds",
          "published",
          "modified"
        ],
        "additionalProperties": false,
        "description": "One vulnerability record."
      },
      "description": "Vulnerabilities matching this package version. An empty array means no known vulnerabilities ONLY when truncated is false."
    },
    "truncated": {
      "type": "boolean",
      "description": "True when OSV returned more result pages than the fetch cap could follow — the vulnerability list may be INCOMPLETE. A truncated empty list is NOT a clean result; raise OSV_QUERY_MAX_PAGES or narrow the query."
    },
    "queryMeta": {
      "type": "object",
      "properties": {
        "package": {
          "type": "string",
          "description": "Queried package name."
        },
        "ecosystem": {
          "type": "string",
          "description": "Queried ecosystem."
        },
        "version": {
          "type": "string",
          "description": "Queried version."
        },
        "vulnCount": {
          "type": "number",
          "description": "Number of vulnerabilities found."
        }
      },
      "required": [
        "package",
        "ecosystem",
        "version",
        "vulnCount"
      ],
      "additionalProperties": false,
      "description": "Query parameters as submitted."
    },
    "notice": {
      "description": "Present on the clean path — confirms no known vulnerabilities for the queried package.",
      "type": "string"
    },
    "effectiveQuery": {
      "description": "The package@version (ecosystem) tuple as queried, echoed for content-only clients.",
      "type": "string"
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `invalid_ecosystem`: The ecosystem string is not recognized by OSV. Ecosystem names are case-sensitive exact matches. Other values are possible when a failure originates below the handler.",
              "examples": [
                "invalid_ecosystem"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "vulns",
        "truncated",
        "queryMeta"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢osv_get_vulnerability(id)

Fetch the full advisory record for an OSV vulnerability ID. Returns the complete record: summary, full details text, CVE aliases, all affected packages and version ranges, fix versions, CVSS severity vectors, CWE weakness IDs, and references. Use when osv_query_package or osv_query_batch returns a vuln ID and you need the full advisory context — eligibility criteria, scope of affected packages, or remediation guidance.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "pattern": "^[A-Za-z][A-Za-z0-9_]*-\\S(.*\\S)?$",
      "description": "One exact, complete OSV advisory ID from any OSV source database, matched case-sensitively. Prefixes include \"GHSA-\" (GitHub), \"PYSEC-\" (PyPI), \"RUSTSEC-\" (Rust), \"GO-\" (Go), \"DSA-\"/\"DLA-\" (Debian), \"USN-\" (Ubuntu), \"RHSA-\" (Red Hat), and \"CVE-\". No wildcards or partial IDs — take IDs from osv_query_package or osv_query_batch results. Example: \"GHSA-29mw-wpgm-hmr9\"."
    }
  },
  "required": [
    "id"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "id": {
      "type": "string",
      "description": "OSV vulnerability ID."
    },
    "summary": {
      "type": "string",
      "description": "One-line advisory description."
    },
    "details": {
      "type": "string",
      "description": "Full advisory text, typically in Markdown. May include proof-of-concept, reproduction steps, or remediation guidance."
    },
    "aliases": {
      "type": "array",
      "items": {
        "type": "string",
        "description": "An alternative ID (usually a CVE ID)."
      },
      "description": "Alternative IDs — usually CVE IDs. Accepted by nvd_get_cve on nist-nvd-mcp-server for CVSS base score, EPSS exploitation probability, and CISA KEV status."
    },
    "published": {
      "type": "string",
      "description": "ISO 8601 timestamp when published."
    },
    "modified": {
      "type": "string",
      "description": "ISO 8601 timestamp of last modification."
    },
    "severity": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "type": {
            "type": "string",
            "description": "Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\"."
          },
          "score": {
            "type": "string",
            "description": "CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\"."
          }
        },
        "required": [
          "type",
          "score"
        ],
        "additionalProperties": false,
        "description": "One record-level severity entry."
      },
      "description": "Record-level severity entries (CVSS vectors, Ubuntu priorities). Empty for unscored advisories and for advisories that score each affected package separately."
    },
    "severityLabel": {
      "description": "Severity label (\"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\") from the first source that yields one: database_specific.severity, an Ubuntu priority, then the highest CVSS v3/v4 score (0.1–3.9 LOW, 4.0–6.9 MODERATE, 7.0–8.9 HIGH, 9.0–10.0 CRITICAL). Uses every affected package severity entry when the record-level list is empty. Null when no source yields a label.",
      "type": [
        "string",
        "null"
      ]
    },
    "severitySource": {
      "anyOf": [
        {
          "type": "object",
          "properties": {
            "type": {
              "type": "string",
              "enum": [
                "database_specific",
                "Ubuntu",
                "CVSS_V3",
                "CVSS_V4"
              ],
              "description": "Source kind: the database_specific.severity label, an Ubuntu priority, or a CVSS vector."
            },
            "score": {
              "type": "string",
              "description": "The published value the label came from: the database_specific.severity text, the Ubuntu priority, or the CVSS vector."
            },
            "computedScore": {
              "description": "CVSS score computed from the vector as published: a CVSS 4.0 vector over every metric group it carries (threat and environmental included), a CVSS 3.x vector with its temporal metrics. Present only for CVSS sources.",
              "type": "number"
            }
          },
          "required": [
            "type",
            "score"
          ],
          "additionalProperties": false
        },
        {
          "type": "null"
        }
      ],
      "description": "The severity entry severityLabel was derived from. Null exactly when the label is."
    },
    "withdrawn": {
      "description": "ISO 8601 timestamp when this advisory was withdrawn. Present ONLY on withdrawn advisories — a withdrawn record has been retracted and must not be treated as an active vulnerability.",
      "type": "string"
    },
    "affected": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "packageName": {
            "type": "string",
            "description": "Affected package name. Empty for source-only advisories (GIT ranges with no package identity)."
          },
          "ecosystem": {
            "type": "string",
            "description": "Affected package ecosystem. Empty for source-only advisories."
          },
          "purl": {
            "description": "Package URL (e.g. \"pkg:npm/lodash\").",
            "type": "string"
          },
          "severity": {
            "description": "Severity entries scoped to this package. Present only when the advisory scores packages separately; the record-level severity is then empty.",
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "type": {
                  "type": "string",
                  "description": "Severity type: \"CVSS_V3\", \"CVSS_V4\", \"CVSS_V2\", or \"Ubuntu\"."
                },
                "score": {
                  "type": "string",
                  "description": "CVSS vector string, or the Ubuntu priority (e.g. \"medium\") for type \"Ubuntu\"."
                }
              },
              "required": [
                "type",
                "score"
              ],
              "additionalProperties": false,
              "description": "One package-level severity entry."
            }
          },
          "versions": {
            "description": "Explicit affected versions enumerated by the advisory. Absent or empty when affected versions are expressed only as ranges.",
            "type": "array",
            "items": {
              "type": "string",
              "description": "An explicitly-listed affected version."
            }
          },
          "ranges": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "rangeType": {
                  "type": "string",
                  "description": "\"SEMVER\", \"ECOSYSTEM\", or \"GIT\"."
                },
                "repo": {
                  "description": "Source repository URL for GIT ranges. Absent on version ranges.",
                  "type": "string"
                },
                "introduced": {
                  "description": "First affected version (convenience view — the last \"introduced\" event; see events[] for full interval order).",
                  "type": "string"
                },
                "fixed": {
                  "description": "The last \"fixed\" event of this range (convenience view — a multi-interval range carries several; see events[]).",
                  "type": "string"
                },
                "lastAffected": {
                  "description": "Last affected version when no fix exists (convenience view — see events[]).",
                  "type": "string"
                },
                "events": {
                  "description": "Ordered event boundaries defining the affected interval(s) — the loss-free view preserving multiple introduced/fixed pairs the scalar fields collapse.",
                  "type": "array",
                  "items": {
                    "type": "object",
                    "properties": {
                      "type": {
                        "type": "string",
                        "description": "Event boundary type: \"introduced\", \"fixed\", \"last_affected\", or \"limit\"."
                      },
                      "value": {
                        "type": "string",
                        "description": "Version string or commit identifier at this boundary."
                      }
                    },
                    "required": [
                      "type",
                      "value"
                    ],
                    "additionalProperties": false,
                    "description": "One ordered range event."
                  }
                }
              },
              "required": [
                "rangeType"
              ],
              "additionalProperties": false,
              "description": "One version range."
            },
            "description": "Version ranges affected."
          }
        },
        "required": [
          "packageName",
          "ecosystem",
          "ranges"
        ],
        "additionalProperties": false,
        "description": "One affected package entry."
      },
      "description": "All affected packages and their version ranges. An advisory may span multiple packages or ecosystems."
    },
    "cweIds": {
      "type": "array",
      "items": {
        "type": "string",
        "description": "A CWE weakness ID."
      },
      "description": "CWE weakness classifications (e.g. [\"CWE-79\"]). Present on GitHub Advisory Database records; empty otherwise."
    },
    "references": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "type": {
            "type": "string",
            "description": "Reference type: \"ADVISORY\", \"WEB\", \"PACKAGE\", \"REPORT\", \"FIX\", \"GIT\", etc."
          },
          "url": {
            "type": "string",
            "description": "URL of the reference."
          }
        },
        "required": [
          "type",
          "url"
        ],
        "additionalProperties": false,
        "description": "One reference entry."
      },
      "description": "Advisory references — NVD links, patches, vendor advisories, PoC reports."
    },
    "schemaVersion": {
      "type": "string",
      "description": "OSV schema version this record conforms to (e.g. \"1.7.3\")."
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode. Declared by this tool: `vulnerability_not_found`: The requested OSV ID does not exist in the database. Other values are possible when a failure originates below the handler.",
              "examples": [
                "vulnerability_not_found"
              ]
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "id",
        "summary",
        "details",
        "aliases",
        "published",
        "modified",
        "severity",
        "severityLabel",
        "severitySource",
        "affected",
        "cweIds",
        "references",
        "schemaVersion"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}
🟢osv_query_batch(packages)

Query vulnerabilities for multiple packages in one call — the primary tool for dependency audits, SBOM scanning, and lockfile triage. Pass an array of {name, ecosystem, version} tuples (up to 1000). Each entry in the response corresponds positionally to the input. Each finding includes CVE aliases for chaining to nist-nvd-mcp-server for CVSS scoring.

Esquema de entrada

{
  "type": "object",
  "properties": {
    "packages": {
      "minItems": 1,
      "maxItems": 1000,
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "pattern": "\\S",
            "description": "Package name as it appears in the ecosystem."
          },
          "ecosystem": {
            "type": "string",
            "pattern": "\\S",
            "description": "Ecosystem identifier. Case-sensitive exact match. Use osv_list_ecosystems to validate."
          },
          "version": {
            "type": "string",
            "pattern": "\\S",
            "description": "Exact version string to check."
          }
        },
        "required": [
          "name",
          "ecosystem",
          "version"
        ],
        "description": "One package to audit."
      },
      "description": "Packages to audit. One entry per dependency. Positional: result[i] corresponds to packages[i]."
    }
  },
  "required": [
    "packages"
  ],
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false
}

Esquema de salida

{
  "type": "object",
  "properties": {
    "results": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "name": {
            "type": "string",
            "description": "Package name from input."
          },
          "ecosystem": {
            "type": "string",
            "description": "Ecosystem from input."
          },
          "version": {
            "type": "string",
            "description": "Version from input."
          },
          "vulnerable": {
            "type": "boolean",
            "description": "True if any vulnerabilities were found."
          },
          "truncated": {
            "type": "boolean",
            "description": "True when OSV paginated beyond the fetch cap for this package — its result may be INCOMPLETE. A truncated row with no vulnerabilities is NOT confirmed clean."
          },
          "error": {
            "description": "Per-package error message (e.g. invalid ecosystem). Null on success.",
            "type": [
              "string",
              "null"
            ]
          },
          "vulnCount": {
            "type": "number",
            "description": "Number of vulnerabilities found. 0 when not vulnerable or on error."
          },
          "vulns": {
            "type": "array",
            "items": {
              "type": "object",
              "properties": {
                "id": {
                  "type": "string",
                  "description": "OSV vulnerability ID."
                },
                "summary": {
                  "type": "string",
                  "description": "One-line advisory description."
                },
                "aliases": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "description": "A CVE ID or other alias."
                  },
                  "description": "CVE IDs and other aliases. Accepted by nist-nvd-mcp-server for CVSS/KEV/EPSS context."
                },
                "severityLabel": {
                  "description": "Severity label: \"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\", or null. Same derivation as osv_query_package: database_specific.severity, then an Ubuntu priority, then the highest CVSS v3/v4 score, using this row's package-level severity entries when the record has none.",
                  "type": [
                    "string",
                    "null"
                  ]
                },
                "fixedVersions": {
                  "type": "array",
                  "items": {
                    "type": "string",
                    "description": "A version that fixes the vulnerability for this package."
                  },
                  "description": "Every fixed version the advisory lists for this row's package, in record order — one per affected interval, typically one per release line. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package."
                }
              },
              "required": [
                "id",
                "summary",
                "aliases",
                "severityLabel",
                "fixedVersions"
              ],
              "additionalProperties": false,
              "description": "One vulnerability found for this package."
            },
            "description": "Vulnerabilities found. Empty array when clean."
          }
        },
        "required": [
          "name",
          "ecosystem",
          "version",
          "vulnerable",
          "truncated",
          "error",
          "vulnCount",
          "vulns"
        ],
        "additionalProperties": false,
        "description": "Result for one package."
      },
      "description": "Per-package results, positionally matching the input array."
    },
    "summary": {
      "type": "object",
      "properties": {
        "totalPackages": {
          "type": "number",
          "description": "Total packages queried."
        },
        "vulnerableCount": {
          "type": "number",
          "description": "Packages with at least one vulnerability."
        },
        "cleanCount": {
          "type": "number",
          "description": "Packages confirmed clean — no vulnerabilities, no error, and not truncated."
        },
        "truncatedCount": {
          "type": "number",
          "description": "Packages whose OSV results were truncated (may be incomplete). A truncated package with no findings is NOT counted as clean."
        },
        "errorCount": {
          "type": "number",
          "description": "Packages that returned an error (e.g. invalid ecosystem)."
        },
        "totalVulns": {
          "type": "number",
          "description": "Total vulnerability instances across all packages (may double-count shared advisories)."
        },
        "worstSeverity": {
          "description": "Highest severity label seen across all findings, or null if no severity data available.",
          "type": [
            "string",
            "null"
          ]
        }
      },
      "required": [
        "totalPackages",
        "vulnerableCount",
        "cleanCount",
        "truncatedCount",
        "errorCount",
        "totalVulns",
        "worstSeverity"
      ],
      "additionalProperties": false,
      "description": "Aggregate statistics across the full batch."
    },
    "notice": {
      "description": "Present on all-clean or all-errors batches — the aggregate outcome for content-only clients.",
      "type": "string"
    },
    "effectiveQuery": {
      "description": "Compact scan summary (package and outcome counts), echoed on edge-case batches for content-only clients.",
      "type": "string"
    },
    "error": {
      "description": "Present when the call failed. Absent on success.",
      "type": "object",
      "properties": {
        "code": {
          "type": "integer",
          "minimum": -9007199254740991,
          "maximum": 9007199254740991,
          "description": "JSON-RPC error code for this failure."
        },
        "message": {
          "type": "string",
          "description": "Human-readable description of what went wrong."
        },
        "data": {
          "type": "object",
          "properties": {
            "reason": {
              "type": "string",
              "description": "Machine-readable failure mode."
            },
            "recovery": {
              "description": "Actionable next step for the caller.",
              "type": "object",
              "properties": {
                "hint": {
                  "type": "string"
                }
              },
              "required": [
                "hint"
              ],
              "additionalProperties": {}
            },
            "retryable": {
              "description": "Whether retrying may succeed.",
              "type": "boolean"
            }
          },
          "additionalProperties": {}
        }
      },
      "required": [
        "code",
        "message"
      ],
      "additionalProperties": {}
    }
  },
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "additionalProperties": false,
  "anyOf": [
    {
      "not": {
        "required": [
          "error"
        ]
      },
      "required": [
        "results",
        "summary"
      ]
    },
    {
      "required": [
        "error"
      ]
    }
  ]
}

Comunidad

Califica este servidor

Evidencia

Observaciones recientes

verificadoversión no registrada4 herramientas
verificadoversión no registrada4 herramientas
verificadoversión no registrada4 herramientas