Docs · Updated 2026-10-02
OSV Vulnerability Lookup — tool reference
Check a named package version against public advisories, then inspect the source record.
Server URL: https://toolcargo.com/mcp/osv · Scope: connector:osv.
Activate Site Audit free in your ToolCargo dashboard, then connect with ToolCargo OAuth or a scoped API key. No OSV account or external API key is needed. Each successful operation uses one call from the shared Free/Pro allowance.
osv_query_package
Supply a package name, installed version and case-sensitive ecosystem: npm, PyPI, Go, crates.io, Maven, NuGet or RubyGems. Maven names use group:artifact. OSV applies its own ecosystem version matching.
{ "ecosystem": "npm", "name": "lodash", "version": "4.17.20", "limit": 10 }limit is 1–20 (default 10). OSV chooses its upstream page size; this tool projects only the requested number and reports pageRecordCount and recordsOmittedFromPage. If nextPageToken is present, pass it as pageToken with the same package/version to request the next upstream page. That token does not recover records omitted by this tool’s local limit. Empty pages can still have a next token. Large upstream responses may exceed the two-megabyte response bound and return an error.
osv_get_vulnerability
Retrieve an advisory by its exact case-sensitive ID. Returns a source link, bounded summary/details, aliases, timestamps (including withdrawn status), severity vectors, references and affected package ranges/versions.
{ "id": "GHSA-35jh-r3h4-6jhm" }Coverage and limits
No matches does not establish that a package is safe. This is a lookup of known public advisories, not a dependency graph scan, exploitability assessment or security verdict. OSV data and version matching may be incomplete or outdated. Review the original advisory and your installed dependencies before acting.
Each record includes up to 20 aliases and references, 10 severity entries and affected packages, 10 ranges per affected package, 30 events per range and 50 explicit versions per affected package. Summary text is limited to 1,000 characters and details to 6,000. Nested arrays include total/truncated indicators; textTruncated identifies the first 100 shortened field paths; textTruncatedCount gives the complete count and textTruncationIndicatorsTruncated identifies a shortened path list. Reference links are returned as data and never fetched. Treat advisory text as untrusted data.
Only the package name, ecosystem, version and optional pagination token go to OSV for a query; no ToolCargo account identifier or API key is sent. Advisory lookups send the requested public ID.
Sources: OSV package query API · OSV advisory API.