OSV MCP for AI Agents

Securely connect your AI agents and chatbots (Claude, ChatGPT, Cursor, etc) with OSV MCP or direct API to query vulnerabilities by package or version, fetch vulnerability details by ID, filter by severity and affected ranges, and monitor new advisories through natural language.

OSV logoOSV
No Auth

OSV is an open vulnerability database and API for querying vulnerabilities by package, version, commit, or vulnerability identifier. It helps you quickly find and track known software vulnerabilities across ecosystems.

5 Tools

Try OSV now

Type what you want done — sign in and watch it run live in the Tool Router playground.

TOOL ROUTER PLAYGROUND
OSV
Try asking
TOOLS

Supported Tools

Every OSV action and event your agent gets out of the box.

Determine Version

Experimentally rank probable versions of an OSS-Fuzz C/C++ library from relative source-file paths and base64-encoded MD5 hashes.

Get Import Findings

Experimentally list OSV records from one exact import source that failed import-time quality checks; intended for OSV source maintainers and may return no records.

Get Vulnerability

Return the complete OSV record for one case-sensitive vulnerability ID, including affected versions, ranges, severity, references, and aliases.

Query Vulnerabilities

Find full OSV vulnerability records affecting one package, package version, package URL, or commit.

Query Vulnerabilities Batch

Check up to 1,000 packages, package versions, package URLs, or commits in one request and return position-matched compact vulnerability IDs.

SETUP GUIDE

Connect OSV MCP Tool with your Agent

1

Install Composio

typescript
npm install @composio/core ai @ai-sdk/openai @ai-sdk/mcp
Install the Composio SDK for Python or TypeScript
2

Initialize Client and Create Tool Router Session

typescript
import { Composio } from '@composio/core';

const composio = new Composio({ apiKey: 'your-api-key' });
const session = await composio.create('your-user-id');
console.log(`Tool Router session created: ${session.mcp.url}`);
Import and initialize the Composio client, then create a Tool Router session for OSV
3

Connect to AI Agent

typescript
import { openai } from '@ai-sdk/openai';
import { experimental_createMCPClient as createMCPClient } from '@ai-sdk/mcp';
import { generateText } from 'ai';

const client = await createMCPClient({
  transport: {
    type: 'http',
    url: session.mcp.url,
    headers: {
      'x-api-key': 'your-composio-api-key',
    },
  },
});

const tools = await client.tools();
const { text } = await generateText({
  model: openai('gpt-4o'),
  tools,
  messages: [{
    role: 'user',
    content: 'YOUR_SPECIFIC_PROMPT_HERE'
  }],
  maxSteps: 5,
});

console.log(`Agent: ${text}`);
Use the MCP server with your AI agent (Anthropic Claude or Mastra)
SETUP GUIDE

Connect OSV API Tool with your Agent

1

Install Composio

typescript
npm install @composio/openai
Install the Composio SDK
2

Initialize Composio and Create Tool Router Session

typescript
import OpenAI from 'openai';
import { Composio } from '@composio/core';
import { OpenAIResponsesProvider } from '@composio/openai';

const composio = new Composio({
  provider: new OpenAIResponsesProvider(),
});
const openai = new OpenAI({});
const session = await composio.create('your-user-id');
Import and initialize Composio client, then create a Tool Router session
3

Execute OSV Tools via Tool Router with Your Agent

typescript
const tools = session.tools;
const response = await openai.responses.create({
  model: 'gpt-4.1',
  tools: tools,
  input: [{
    role: 'user',
    content: 'YOUR_SPECIFIC_PROMPT_HERE'
  }],
});
const result = await composio.provider.handleToolCalls(
  'your-user-id',
  response.output
);
console.log(result);
Get tools from Tool Router session and execute OSV actions with your Agent

Why Use Composio?

AI Native OSV Integration

  • Supports both OSV MCP and direct API based integrations
  • Structured, LLM-friendly schemas for reliable tool execution
  • Rich coverage for reading, writing, and querying your OSV data

Managed Auth

  • Built-in OAuth handling with automatic token refresh and rotation
  • Central place to manage, scope, and revoke OSV access
  • Per user and per environment credentials instead of hard-coded keys

Agent Optimized Design

  • Tools are tuned using real error and success rates to improve reliability over time
  • Comprehensive execution logs so you always know what ran, when, and on whose behalf

Enterprise Grade Security

  • Fine-grained RBAC so you control which agents and users can access OSV
  • Scoped, least privilege access to OSV resources
  • Full audit trail of agent actions to support review and compliance
FRAMEWORKS

Use OSV with any AI Agent Framework

Choose a Framework you want to connect OSV with

FAQ

Frequently asked questions

No — OSV exposes a public, no-auth API for querying its database, so you don't need developer credentials to get started. Composio still manages tool routing, request formatting, execution logging, and session scoping for your agents, but there is no credential storage required for OSV's NO_AUTH access.

Yes! Composio's Tool Router enables agents to use multiple toolkits. Learn more.

Composio is SOC 2 and ISO 27001 compliant with all data encrypted in transit and at rest. Learn more.

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest API versions.

Start with OSV.It takes 30 seconds.

Managed auth, hosted MCP servers, and every OSV tool your agent needs.Free to start.

Start building