Vulnerability scan
vulnerability_scanScan project lockfiles for OSV.dev vulnerabilities, including transitive dependencies, with fix versions and where each is pinned. Check security, CVEs, or a single package before adding a dependency.
Instructions
Scan this project's lockfiles (npm/pnpm/yarn/bun, Cargo, Python, Go) for known OSV.dev vulnerabilities, transitives included, with fix versions and where each is pinned; package for one dep. Call when the user asks about security, vulnerabilities or CVEs, or before recommending a dependency.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| package | No | Only this package (any ecosystem, every installed copy, transitives included), with a `package_note` saying what the lockfiles hold for it. Use it to ask about one dependency instead of reading the whole report. | |
| include_dev | No | Include known direct devDependencies. Transitive dev/runtime scope may be unknown. Default: false. | |
| project_path | No | Project directory to scan. Default: current working directory. | |
| force_refresh | No | Ignore the OSV advisory cache and fetch fresh advisory data from OSV.dev (dependency versions are re-read on every lockfile change regardless). Default: false. | |
| response_format | No | concise (default): one row per vulnerable package version (worst severity, the version that fixes all its advisories, advisory count and first ids, where it is pinned), the 40 most severe and 25 recommendations, with counts of anything left out. detailed: one row per advisory with references, plus platform-inactive advisories, maintenance notices, install drift and resolution provenance. | |
| severity_filter | No | Only show vulnerabilities whose presented severity is at or above this level. |