Skip to main content
Glama

Server Details

OSV.dev — Google's open-source vulnerability database

If you are the author of this connector, you can claim ownership with GitHub, an HTTP challenge, or a DNS record. Claimed connector authors can inspect health checks, view analytics, and manage their listing.
Status
Unhealthy
Last Tested
Transport
Streamable HTTP
URL
Repository
pipeworx-io/mcp-osv-dev
GitHub Stars
0
Server Listing
mcp-osv-dev

Frequently Asked Questions

Discussions

No comments yet. Be the first to start the discussion!

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    Visual CVE audit dashboard for npm, Python, Go, and Rust projects. Scans your project manifests (package-lock.json, requirements.txt, go.sum, Cargo.lock) against OSV.dev live data, opens a browser dashboard for human review, then applies fixes only after explicit confirmation. Supports multi-service monorepos in one command.
    4
    12
    4
    MIT
  • A
    license
    A
    quality
    D
    maintenance
    Automatically scans project dependencies (npm, Composer) for security vulnerabilities using the OSV.dev database, providing real-time alerts and detailed remediation guidance directly in your IDE.
    1
    11
    1
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Query OSV.dev for package vulnerabilities, batch-audit dependency lists, and fetch full advisory records via MCP.
    145
    1
    Apache 2.0
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

TDQS

A4.1/5.0
Disambiguation3/5

Several tools form overlapping clusters that could confuse an agent: the three ask_pipeworx variants (base, beta, grounded) serve nearly identical routing purposes with beta explicitly identical to base, and the five polymarket_* tools cover related but distinct trading-adjacent functions. Descriptions are detailed and mostly disambiguate, but the sheer number of similar-sounding tools (31) increases the risk of misselection.

Naming Consistency4/5

All names use snake_case and are descriptive, but the semantic pattern is inconsistent: some are verb_noun (compare_entities, discover_tools), some noun_noun (entity_profile, polymarket_edge_tracker), some single verbs (remember, recall, forget), and some adjective_noun (deep_research, recent_alerts). This mix is readable but lacks the uniform verb_noun structure of the high-coherence calibration example.

Tool Count3/5

31 tools is above the 25+ threshold that feels heavy for most servers, but this is a comprehensive data-aggregation platform exposing a curated subset of 5,621 internal tools. The breadth justifies many of them, yet from an agent's perspective the surface is dense and could overwhelm; a more focused set with fewer overlapping utilities would improve usability.

Completeness4/5

The surface covers a wide range of domain operations: data lookup (ask_pipeworx), research (deep_research), entity profiling and comparison, claim verification, prediction markets, subscriptions, memory, and discovery. Minor gaps exist—for example, there is no explicit tool to fetch a raw record by pipeworx:// URI (though search_within can search inside already-fetched text), and web utilities like generate_llms_txt and scan_dependency feel tangential. Overall the core data workflows are well covered.