Skip to content

Claude Code osv advisory mcp server osv_get_vulnerability

How to: Claude Code osv advisory mcp server osv_get_vulnerability

client:Claude Code transport:streamable-http tool:osv_get_vulnerability

Add osv advisory mcp server to Claude Code

  1. 01

    Run this in your project directory.

claude mcp add --transport http osv-advisory-mcp-server https://osv-advisory.caseyjhand.com/mcp
  1. 02

    Restart your session so the server is picked up.

  2. 03

    Ask for something osv_get_vulnerability does. Claude Code lists the server's tools on connect and calls osv_get_vulnerability itself — you do not invoke it by name.

  3. 04

    If nothing happens, check the server is running and that osv advisory mcp server's identifier in your config matches the one above exactly.

Adds it for this project only. Append --scope user to make it available everywhere. Claude Code docs

Set these first

osv advisory mcp server will not start until these are set, so osv_get_vulnerability never becomes available.

  • OSV_REQUEST_TIMEOUT_MS
  • OSV_BATCH_CONCURRENCY
  • OSV_QUERY_MAX_PAGES
  • MCP_LOG_LEVEL

Same tool, other clients

This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what the server actually exposes, not what its listing claims.

Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.