Mcp Osv Dev — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Osv Dev (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
OSV.dev MCP — Google's open-source vulnerability database.
Part of Pipeworx — an MCP gateway connecting AI agents to 673+ live data sources.
| Tool | Description |
|---|---|
vulnerabilities | Query vulnerabilities by package (+ optional version) or git commit. |
query_batch | Batch query (≤1000 queries). Pass an array of {package: {name, ecosystem}, version?} or {commit}. |
get | Full vulnerability record by id (CVE-…, GHSA-…, OSV-…). |
Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):
{
"mcpServers": {
"osv-dev": {
"url": "https://gateway.pipeworx.io/osv-dev/mcp"
}
}
}Or connect to the full Pipeworx gateway for access to all 673+ data sources:
{
"mcpServers": {
"pipeworx": {
"url": "https://gateway.pipeworx.io/mcp"
}
}
}Instead of calling tools directly, you can ask questions in plain English:
ask_pipeworx({ question: "your question about Osv Dev data" })The gateway picks the right tool and fills the arguments automatically.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.