io.github.cyanheads/osv-advisory-mcp-server
Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.
Verdict not yet evaluated for this tool. The hybrid eval runs adversarial cases first; coverage rolls out as the corpus expands (15 of 150 labels to graduation). Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: hybrid eval, four-state verdict, honest limits.
OSV_REQUEST_TIMEOUT_MSHTTP request timeout in milliseconds for OSV.dev API calls.
MCP_LOG_LEVELSets the minimum log level for output (e.g., 'debug', 'info', 'warn').
OSV_REQUEST_TIMEOUT_MSHTTP request timeout in milliseconds for OSV.dev API calls.
MCP_HTTP_HOSTThe hostname for the HTTP server.
MCP_HTTP_PORTThe port to run the HTTP server on.
MCP_HTTP_ENDPOINT_PATHThe endpoint path for the MCP server.
MCP_AUTH_MODEAuthentication mode to use: 'none', 'jwt', or 'oauth'.
MCP_LOG_LEVELSets the minimum log level for output (e.g., 'debug', 'info', 'warn').
Security tools for AI agents: scan MCP servers, validate HDP delegation chains, audit releases.
Provide AI-powered real-time analysis and intelligence on NPM packages, including security, depend…
Zenable cleans up sloppy AI code and prevents vulnerabilities with deterministic guardrails