MCP server · Security
OSV MCP server
by StacklokLabs
Lets your AI check the OSV database for known security problems in software packages and versions.

This is a small helper that connects your AI assistant to the OSV database, a public list of known security flaws in open source software. You ask your AI something like "is this version of lodash safe?" and it looks up the answer for you. It is handy for anyone who works with software packages and wants a quick check without opening a browser.
What is an MCP server? The 30-second version
On its own, your AI can only chat with you using what it already knows. An MCP server is a small helper program that gives your AI a new skill or a connection to another service. This one connects your AI to the OSV database, a public catalogue of known security problems in software packages. Once it is connected, your AI can look things up there for you when you ask.
What this MCP server does
You ask your AI a question about a package, a version, or a specific code commit. The AI passes that question to this helper. The helper talks to the OSV database over the internet and fetches the matching vulnerability records. The AI then reads those records and explains them back to you in the chat, in plain words. You can also ask about several packages at once, or ask for the full details of one vulnerability by its ID.
Click to zoomWhat you can do with it
- Check whether a specific package version has known vulnerabilities
- Check a code commit for known vulnerabilities
- Check several packages or versions in one go
- Look up the details of a vulnerability by its ID
- Get a plain-language summary of what each vulnerability means
- Compare results across different ecosystems like npm, PyPI, or Go
Try asking your AI
- “Does lodash 4.17.15 have any known security issues?”
- “Check these packages for vulnerabilities: lodash 4.17.15 in npm and jinja2 2.4.1 in PyPI”
- “What is GHSA-vqj2-4v8m-8vrq about?”
- “Are there any known problems with the commit 6879efc2c1596d11a6a6ad296f80063b558d5e0f?”
What it gives back to you
You get back a list of vulnerability records that match your question, or a single detailed record if you asked by ID. Each record usually includes the vulnerability ID, a short description, and which versions are affected. Your AI will typically summarise this for you in the chat and can show the raw details if you ask.
Before you start
What you need
- An MCP-compatible AI client (such as the Claude desktop app or another tool that supports MCP servers)
- ToolHive installed if you want the easy containerised setup, or Go 1.21 or later if you build it yourself
Good to know
The information comes from a public database and may not be complete or up to date, so treat it as a starting point rather than a final security verdict.
Install it with your AI
Add OSV MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check OSV MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Developers, IT and security staff, and anyone who needs a quick check on whether a software package or version has known security problems.





