Gemini CLI osv advisory mcp server osv_get_vulnerability
How to: Gemini CLI osv advisory mcp server osv_get_vulnerability
Add osv advisory mcp server to Gemini CLI
-
01
Open ~/.gemini/settings.json and merge this in. Keep any servers already there.
{
"mcpServers": {
"osv-advisory-mcp-server": {
"httpUrl": "https://osv-advisory.caseyjhand.com/mcp"
}
}
}
-
02
Save the file and restart Gemini CLI.
-
03
Ask for something osv_get_vulnerability does. Gemini CLI lists the server's tools on connect and calls osv_get_vulnerability itself — you do not invoke it by name.
-
04
If nothing happens, check the server is running and that osv advisory mcp server's identifier in your config matches the one above exactly.
Gemini expands $VAR and ${VAR} inside env values, so a secret can live in your shell rather than this file. Gemini CLI docs
Set these first
osv advisory mcp server will not start until these are set, so osv_get_vulnerability never becomes available.
-
OSV_REQUEST_TIMEOUT_MS -
OSV_BATCH_CONCURRENCY -
OSV_QUERY_MAX_PAGES -
MCP_LOG_LEVEL
Same tool, other clients
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.