Osv Advisory MCP Server
by cyanheadsio.github.cyanheads/osv-advisory-mcp-serverv0.1.15
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
context tax
queued
security
queued
cold start
queued
freshness
Active15d ago
Install Osv Advisory MCP server
Install in Claude Code
claude mcp add osv-advisory -- npx -y @cyanheads/osv-advisory-mcp-server run start:stdioInstall in Cursor
{
"mcpServers": {
"osv-advisory": {
"command": "npx",
"args": [
"-y",
"@cyanheads/osv-advisory-mcp-server",
"run",
"start:stdio"
]
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"osv-advisory": {
"command": "npx",
"args": [
"-y",
"@cyanheads/osv-advisory-mcp-server",
"run",
"start:stdio"
]
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"osv-advisory": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@cyanheads/osv-advisory-mcp-server",
"run",
"start:stdio"
]
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"osv-advisory": {
"command": "npx",
"args": [
"-y",
"@cyanheads/osv-advisory-mcp-server",
"run",
"start:stdio"
]
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| OSV_REQUEST_TIMEOUT_MS | — | — | HTTP request timeout in milliseconds for OSV.dev API calls. |
| OSV_BATCH_CONCURRENCY | — | — | Maximum number of concurrent OSV.dev requests issued by osv_query_batch. |
| OSV_QUERY_MAX_PAGES | — | — | Maximum number of OSV.dev result pages osv_query_package follows before marking a result truncated. |
| MCP_LOG_LEVEL | — | — | Sets the minimum log level for output (e.g., 'debug', 'info', 'warn'). |
| MCP_HTTP_HOST | — | — | The hostname for the HTTP server. |
| MCP_HTTP_PORT | — | — | The port to run the HTTP server on. |
| MCP_HTTP_ENDPOINT_PATH | — | — | The endpoint path for the MCP server. |
| MCP_AUTH_MODE | — | — | Authentication mode to use: 'none', 'jwt', or 'oauth'. |
| MCP_SESSION_MODE | — | — | HTTP session mode. This server deploys stateless because its tools do not use multi-round input. |
Remote endpoints
- streamable-http
https://osv-advisory.caseyjhand.com/mcp
Freshness
Active — last maintenance signal 15d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-24 · 15d ago · GitHub
Latest release
2026-09-24 · 15d ago · GitHub · v0.1.15
Package published
no data · npm/PyPI
Registry entry updated
2026-09-24 · 15d ago · official registry · v0.1.15
FAQ
›How do I install the Osv Advisory MCP server in Claude Code?
Run: claude mcp add osv-advisory -- npx -y @cyanheads/osv-advisory-mcp-server run start:stdio. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Osv Advisory require an API key?
No required environment variables are declared in its published metadata.
›Can I use Osv Advisory as a remote (hosted) MCP server?
Yes — it offers both a hosted endpoint and a local stdio package.
›Is Osv Advisory in the official MCP registry?
Yes, as io.github.cyanheads/osv-advisory-mcp-server.