Cursor osv advisory mcp server osv_query_package
How to: Cursor osv advisory mcp server osv_query_package
Add osv advisory mcp server to Cursor
-
01
Open ~/.cursor/mcp.json and merge this in. Keep any servers already there.
{
"mcpServers": {
"osv-advisory-mcp-server": {
"url": "https://osv-advisory.caseyjhand.com/mcp"
}
}
}
-
02
Save the file and restart Cursor.
-
03
Ask for something osv_query_package does. Cursor lists the server's tools on connect and calls osv_query_package itself — you do not invoke it by name.
-
04
If nothing happens, check the server is running and that osv advisory mcp server's identifier in your config matches the one above exactly.
Use .cursor/mcp.json in a project root instead to scope it to that project. Cursor merges both. Cursor docs
Set these first
osv advisory mcp server will not start until these are set, so osv_query_package never becomes available.
-
OSV_REQUEST_TIMEOUT_MS -
OSV_BATCH_CONCURRENCY -
OSV_QUERY_MAX_PAGES -
MCP_LOG_LEVEL
Same tool, other clients
This list was read from the server itself, by connecting to it and calling tools/list on 24 September 2026. It is what
the server actually exposes, not what its listing claims.
Mutating and Read-only are read off each tool's name, not its schema — a hint, not a guarantee. The registry stores tool names only; connect the server for its live schemas.