OSV MCP server for AI agents and assistants

Securely connect your AI agents and chatbots (Claude, ChatGPT, Cursor, etc) with OSV MCP or direct API to query vulnerabilities by package or version, fetch vulnerability details by ID, filter by severity and affected ranges, and monitor new advisories through natural language.

OSV logoOSV
No Auth

OSV is an open vulnerability database and API for querying vulnerabilities by package, version, commit, or vulnerability identifier. It helps you quickly find and track known software vulnerabilities across ecosystems.

5 Tools

Try OSV now

Type what you want done — sign in and watch it run live in the Tool Router playground.

TOOL ROUTER PLAYGROUND
OSV
Try asking
TOOLS

Supported Tools

Every OSV action and event your agent gets out of the box.

Determine Version

Experimentally rank probable versions of an OSS-Fuzz C/C++ library from relative source-file paths and base64-encoded MD5 hashes.

Get Import Findings

Experimentally list OSV records from one exact import source that failed import-time quality checks; intended for OSV source maintainers and may return no records.

Get Vulnerability

Return the complete OSV record for one case-sensitive vulnerability ID, including affected versions, ranges, severity, references, and aliases.

Query Vulnerabilities

Find full OSV vulnerability records affecting one package, package version, package URL, or commit.

Query Vulnerabilities Batch

Check up to 1,000 packages, package versions, package URLs, or commits in one request and return position-matched compact vulnerability IDs.

SETUP GUIDE

Connect OSV MCP Tool with your Agent

1

Install Composio

typescript
npm install @composio/core ai @ai-sdk/mcp @ai-sdk/openai
Install the Composio SDK and your agent framework
2

Create a session with MCP enabled

typescript
import { Composio } from "@composio/core";

const composio = new Composio();
const { mcp } = await composio.create("your-user-id", {
  toolkits: ["osv"],
  mcp: true,
});
Create a session scoped to OSV and read its MCP URL and headers
3

Connect your agent to the MCP server

typescript
import { createMCPClient } from "@ai-sdk/mcp";
import { openai } from "@ai-sdk/openai";
import { generateText, stepCountIs } from "ai";

const client = await createMCPClient({
  transport: { type: "http", url: mcp.url, headers: mcp.headers },
});

const { text } = await generateText({
  model: openai("gpt-5.6-sol"),
  tools: await client.tools(),
  prompt: "List all vulnerabilities for package django",
  stopWhen: stepCountIs(10),
});

console.log(text);
await client.close();
Pass the session's MCP URL and headers to your agent and run a OSV request
SETUP GUIDE

Connect OSV API Tool with your Agent

1

Install Composio

typescript
npm install @composio/core @composio/openai openai
Install the Composio SDK, the OpenAI provider, and the OpenAI SDK
2

Create a Composio session

typescript
import OpenAI from "openai";
import { Composio } from "@composio/core";
import { OpenAIResponsesProvider } from "@composio/openai";

const composio = new Composio({ provider: new OpenAIResponsesProvider() });
const client = new OpenAI();

const session = await composio.create("your-user-id", { toolkits: ["osv"] });
const tools = await session.tools();
Initialize Composio with the OpenAI Responses provider and create a session scoped to OSV
3

Run OSV tools with your agent

typescript
let response = await client.responses.create({
  model: "gpt-5.6-sol",
  tools,
  input: [{ role: "user", content: "List all vulnerabilities for package django" }],
});

while (response.output.some((o) => o.type === "function_call")) {
  const outputs = await composio.provider.handleToolCalls(session, response.output);
  response = await client.responses.create({
    model: "gpt-5.6-sol",
    tools,
    previous_response_id: response.id,
    input: outputs,
  });
}

console.log(response.output_text);
Send a request, execute the OSV tool calls through the session, and print the final answer

Why Use Composio?

AI Native OSV Integration

  • Supports both OSV MCP and direct API based integrations
  • Structured, LLM-friendly schemas for reliable tool execution
  • Rich coverage for reading, writing, and querying your OSV data

Managed Auth

  • Built-in OAuth handling with automatic token refresh and rotation
  • Central place to manage, scope, and revoke OSV access
  • Per user and per environment credentials instead of hard-coded keys

Agent Optimized Design

  • Tools are tuned using real error and success rates to improve reliability over time
  • Comprehensive execution logs so you always know what ran, when, and on whose behalf

Enterprise Grade Security

  • Fine-grained RBAC so you control which agents and users can access OSV
  • Scoped, least privilege access to OSV resources
  • Full audit trail of agent actions to support review and compliance

Rolling this out across your team?

Give your team centralized access control across every framework with Composio’s MCP Gateway.

EXPLORE MCP GATEWAY
FAQ

Frequently asked questions

No — OSV exposes a public, no-auth API for querying its database, so you don't need developer credentials to get started. Composio still manages tool routing, request formatting, execution logging, and session scoping for your agents, but there is no credential storage required for OSV's NO_AUTH access.

Yes! Composio's Tool Router enables agents to use multiple toolkits. Learn more.

Yes. Composio is SOC 2 Type II compliant and is built to keep your OSV connection and credentials secure. OAuth tokens and API keys are encrypted, and sensitive customer data is protected at rest and in transit.

Composio also undergoes independent security testing and continuously monitors its systems for security threats. You can review the latest reports and policies in the Composio Trust Center.

Composio maintains and updates all toolkit integrations automatically, so your agents always work with the latest API versions.

When you connect a OSV account through Composio, every action runs under that account, so anything the agent creates, sends, or changes shows up in OSV as done by you. Keep an approval step in your prompt for actions with side effects, such as sending or deleting, and have the agent draft first.

Whatever the credentials you connect allow inside OSV. If OSV lets you scope a key to specific permissions, create a scoped one so the agent can only do what you intend. You can revoke the key inside OSV at any time.

Yes. Composio supports multiple connected accounts for the same app, and that works in Claude, ChatGPT, or any other assistant you connect through Composio. Give each OSV connection a name such as work or personal, and the assistant uses the one you mention in the request. Each account keeps its own credentials and nothing is merged.

Composio's free Hobby plan includes 100,000 tool calls per month with no credit card, which covers most personal OSV use. Paid plans add higher limits and team features. Your OSV plan and its API limits still apply as usual.

Built-in connectors usually give one AI access to a limited set of apps. Many people use Composio because it lets their AI connect to more apps than it normally supports, or connect to multiple accounts for the same app (e.g. connect Claude to multiple OSV accounts).

With Composio, you connect OSV once and then use it across different AI assistants without setting it up separately in each one. Connect your apps to Composio once, then connect Composio to whichever AI you use, whether that's Claude, ChatGPT, Hermes, or your own custom assistant.

Start with OSV.It takes 30 seconds.

Managed auth, hosted MCP servers, and every OSV tool your agent needs.Free to start.

Start building