Skip to main content
Glama

Osv Query Batch

osv_query_batch
Read-onlyIdempotent

Query vulnerabilities for multiple packages in one call — the primary tool for dependency audits, SBOM scanning, and lockfile triage. Pass an array of {name, ecosystem, version} tuples (up to 1000). Each entry in the response corresponds positionally to the input. Each finding includes CVE aliases for chaining to nist-nvd-mcp-server for CVSS scoring.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
packagesYesPackages to audit. One entry per dependency. Positional: result[i] corresponds to packages[i].

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault
errorNoPresent when the call failed. Absent on success.
noticeNoPresent on all-clean or all-errors batches — the aggregate outcome for content-only clients.
resultsNoPer-package results, positionally matching the input array.
summaryNoAggregate statistics across the full batch.
effectiveQueryNoCompact scan summary (package and outcome counts), echoed on edge-case batches for content-only clients.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed6 schema fields changed
    • removedInput schema / properties / packages / items / properties / ecosystem / minLength
      Removed value: -1
    • removedInput schema / properties / packages / items / properties / name / minLength
      Removed value: -1
    • removedInput schema / properties / packages / items / properties / version / minLength
      Removed value: -1
    • changedOutput schema / properties / results / items / properties / vulns / items / properties / fixedVersions / description
      Previous value: -"First safe version(s) to upgrade to. Empty if no fix exists."New value: +"Every fixed version the advisory lists for this row's package, in record order — one per affected interval, typically one per release line. Excludes other packages' fixes and GIT commits. Empty when the advisory lists no fix for this package."
    • changedOutput schema / properties / results / items / properties / vulns / items / properties / fixedVersions / items / description
      Previous value: -"A first-safe version string."New value: +"A version that fixes the vulnerability for this package."
    • changedOutput schema / properties / results / items / properties / vulns / items / properties / severityLabel / description
      Previous value: -"Severity label: \"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\", or null."New value: +"Severity label: \"LOW\", \"MODERATE\", \"HIGH\", \"CRITICAL\", or null. Same derivation as osv_query_package: database_specific.severity, then an Ubuntu priority, then the highest CVSS v3/v4 score, using this row's package-level severity entries when the record has none."
  2. Changed6 schema fields changed
    • removedOutput schema / properties / results / items / properties / error / anyOf
      Removed value: -[
      -  {
      -    "type": "string"
      -  },
      -  {
      -    "type": "null"
      -  }
      -]
    • addedOutput schema / properties / results / items / properties / error / type
      Added value: +[
      +  "string",
      +  "null"
      +]
    • removedOutput schema / properties / results / items / properties / vulns / items / properties / severityLabel / anyOf
      Removed value: -[
      -  {
      -    "type": "string"
      -  },
      -  {
      -    "type": "null"
      -  }
      -]
    • addedOutput schema / properties / results / items / properties / vulns / items / properties / severityLabel / type
      Added value: +[
      +  "string",
      +  "null"
      +]
    • removedOutput schema / properties / summary / properties / worstSeverity / anyOf
      Removed value: -[
      -  {
      -    "type": "string"
      -  },
      -  {
      -    "type": "null"
      -  }
      -]
    • addedOutput schema / properties / summary / properties / worstSeverity / type
      Added value: +[
      +  "string",
      +  "null"
      +]
  3. Changed6 schema fields changed
    • changedInput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
    • addedInput schema / additionalProperties
      Added value: +false
    • changedOutput schema / $schema
      Previous value: -"http://json-schema.org/draft-07/schema#"New value: +"https://json-schema.org/draft/2020-12/schema"
    • addedOutput schema / anyOf
      Added value: +[
      +  {
      +    "not": {
      +      "required": [
      +        "error"
      +      ]
      +    },
      +    "required": [
      +      "results",
      +      "summary"
      +    ]
      +  },
      +  {
      +    "required": [
      +      "error"
      +    ]
      +  }
      +]
    • addedOutput schema / properties / error
      Added value: +{
      +  "additionalProperties": {},
      +  "description": "Present when the call failed. Absent on success.",
      +  "properties": {
      +    "code": {
      +      "description": "JSON-RPC error code for this failure.",
      +      "maximum": 9007199254740991,
      +      "minimum": -9007199254740991,
      +      "type": "integer"
      +    },
      +    "data": {
      +      "additionalProperties": {},
      +      "properties": {
      +        "reason": {
      +          "description": "Machine-readable failure mode.",
      +          "type": "string"
      +        },
      +        "recovery": {
      +          "additionalProperties": {},
      +          "description": "Actionable next step for the caller.",
      +          "properties": {
      +            "hint": {
      +              "type": "string"
      +            }
      +          },
      +          "required": [
      +            "hint"
      +          ],
      +          "type": "object"
      +        },
      +        "retryable": {
      +          "description": "Whether retrying may succeed.",
      +          "type": "boolean"
      +        }
      +      },
      +      "type": "object"
      +    },
      +    "message": {
      +      "description": "Human-readable description of what went wrong.",
      +      "type": "string"
      +    }
      +  },
      +  "required": [
      +    "code",
      +    "message"
      +  ],
      +  "type": "object"
      +}
    • removedOutput schema / required
      Removed value: -[
      -  "results",
      -  "summary"
      -]
  4. Changed6 schema fields changed
    • addedInput schema / properties / packages / items / properties / ecosystem / minLength
      Added value: +1
    • addedInput schema / properties / packages / items / properties / ecosystem / pattern
      Added value: +"\\S"
    • addedInput schema / properties / packages / items / properties / name / minLength
      Added value: +1
    • addedInput schema / properties / packages / items / properties / name / pattern
      Added value: +"\\S"
    • addedInput schema / properties / packages / items / properties / version / minLength
      Added value: +1
    • addedInput schema / properties / packages / items / properties / version / pattern
      Added value: +"\\S"
  5. Changed5 schema fields changed
    • addedOutput schema / properties / results / items / properties / truncated
      Added value: +{
      +  "description": "True when OSV paginated beyond the fetch cap for this package — its result may be INCOMPLETE. A truncated row with no vulnerabilities is NOT confirmed clean.",
      +  "type": "boolean"
      +}
    • changedOutput schema / properties / results / items / required
      Previous value: -[
      -  "name",
      -  "ecosystem",
      -  "version",
      -  "vulnerable",
      -  "error",
      -  "vulnCount",
      -  "vulns"
      -]New value: +[
      +  "name",
      +  "ecosystem",
      +  "version",
      +  "vulnerable",
      +  "truncated",
      +  "error",
      +  "vulnCount",
      +  "vulns"
      +]
    • changedOutput schema / properties / summary / properties / cleanCount / description
      Previous value: -"Packages with no vulnerabilities."New value: +"Packages confirmed clean — no vulnerabilities, no error, and not truncated."
    • addedOutput schema / properties / summary / properties / truncatedCount
      Added value: +{
      +  "description": "Packages whose OSV results were truncated (may be incomplete). A truncated package with no findings is NOT counted as clean.",
      +  "type": "number"
      +}
    • changedOutput schema / properties / summary / required
      Previous value: -[
      -  "totalPackages",
      -  "vulnerableCount",
      -  "cleanCount",
      -  "errorCount",
      -  "totalVulns",
      -  "worstSeverity"
      -]New value: +[
      +  "totalPackages",
      +  "vulnerableCount",
      +  "cleanCount",
      +  "truncatedCount",
      +  "errorCount",
      +  "totalVulns",
      +  "worstSeverity"
      +]
  6. Changed2 schema fields changed
    • addedOutput schema / properties / effectiveQuery
      Added value: +{
      +  "description": "Compact scan summary (package and outcome counts), echoed on edge-case batches for content-only clients.",
      +  "type": "string"
      +}
    • addedOutput schema / properties / notice
      Added value: +{
      +  "description": "Present on all-clean or all-errors batches — the aggregate outcome for content-only clients.",
      +  "type": "string"
      +}
  7. Changed2 schema fields changed
    • removedInput schema / properties / canvas_id
      Removed value: -{
      -  "description": "Reuse an existing DataCanvas table token to append results. Omit to create a new canvas. Only relevant when package count >= 200.",
      -  "type": "string"
      -}
    • removedOutput schema / properties / canvas_id
      Removed value: -{
      -  "description": "DataCanvas table token. Present when the package count is >= 200 or a canvas_id was provided. Use to run SQL queries across the full result set via the canvas tools.",
      -  "type": "string"
      -}
  8. First observed

TDQS

A4.3/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The annotations already declare readOnlyHint and idempotentHint, so the description does not need to restate safety. It adds useful behavioral context: responses are positional, the batch supports up to 1000 packages, and findings include CVE aliases for chaining to nist-nvd-mcp-server. This goes beyond the structured annotations without contradicting them.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three tightly packed sentences: the first establishes the tool's primary role, the second specifies input shape and limits, and the third explains output correspondence and chaining. Every sentence earns its place with no redundant elaboration.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Given the presence of an output schema, full parameter coverage in the input schema, and annotations covering safety and idempotency, the description provides everything needed to select and invoke the tool correctly. It also adds cross-server chaining guidance, which is valuable contextual information.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, with the packages array and its nested fields already well documented. The description reinforces the tuple shape and positional semantics, but most of this information is already present in the schema, so the added value is limited to emphasis rather than new detail.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description uses a specific verb ('Query vulnerabilities') with a clear resource ('multiple packages in one call') and immediately identifies its main use cases: dependency audits, SBOM scanning, and lockfile triage. This makes it easy to distinguish from the sibling tools, especially osv_query_package, since batch behavior is called out up front.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly frames the tool as 'the primary tool for dependency audits, SBOM scanning, and lockfile triage', giving clear context on when to reach for it. It does not explicitly name alternatives or state when not to use it, but the 'primary tool' wording combined with the batch focus provides adequate usage direction.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.