oo-osvOSV (osv.dev). Use this skill for ANY OSV request — searching and reading data. Whenever a task involves OSV, use this skill instead of calling the API directly.
Install via ClawdBot CLI:
clawdbot install oomol/oo-osvGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
curl -fsSL https://cli.oomol.com/install.sh | bashCalls external URL not in known-safe list
https://static.oomol.com/logo/third-party/osv.svgAudited Oct 3, 2026 · audit v1.0
Generated Oct 3, 2026
Engineering teams embed the OSV skill into their build pipelines to query vulnerabilities for packages and pinned versions before a release. When a dependency is flagged, the agent fetches the full OSV record to determine severity and affected version ranges. This gates deployments on known CVE exposure without manually checking osv.dev.
Security analysts use the skill to cross-reference a generated software bill of materials against OSV's database, enriching each component with vulnerability metadata. Compliance teams then produce audit-ready reports mapping dependencies to advisories. This supports frameworks like Executive Order 14028 and internal supply-chain policies.
Open-source maintainers query OSV by package name to discover new advisories affecting their projects and downstream users. The agent retrieves complete vulnerability records and surfaces them in issue trackers or release notes. Maintainers can respond quickly with patches and version advisories.
Threat researchers look up OSV records by identifier to gather ecosystem, aliases, references, and affected ranges for a given vulnerability. They aggregate this data into intelligence feeds or dashboards tracking emerging CVEs across package ecosystems. The skill removes the need to parse raw OSV API responses manually.
Developers assess risk before bumping a library by querying OSV for the target version's vulnerability status. The agent compares current and proposed versions to show whether an upgrade resolves known issues or introduces new exposures. This informs approval decisions in package upgrade pull requests.
Small and mid-sized companies lacking dedicated security teams subscribe to a managed service that continuously scans their dependency manifests against OSV. The provider delivers prioritized vulnerability alerts and remediation guidance. Value is delivered through reduced breach risk without in-house tooling.
Existing CI/CD or code-hosting platforms license the OSV integration as an add-on feature for enterprise customers. It enriches pull requests and builds with vulnerability context directly in the developer workflow. This increases platform stickiness and upsell revenue.
Auditors and compliance consultancies use the skill to automate SBOM vulnerability evidence collection for certification processes like SOC 2 or ISO 27001. They sell audit readiness reports and continuous monitoring retainers. The OSV integration reduces manual evidence-gathering hours.
💬 Integration Tip
Always run `oo connector schema "osv" --action "<action_name>"` before building a payload to get the authoritative input fields, and use `--json` so you can parse the response and capture `meta.executionId` for traceability.
Scored Oct 3, 2026
Real-time search engine supporting web search, vertical domain search, parallel batch search, and URL content extraction.
Manage Feishu (Lark) calendars by listing, searching, checking schedules, syncing events, and marking tasks with automated date extraction.
cad reference tool
Search, install, and create OpenClaw skills using intelligent matching across built-in, local, and GitHub skill repositories.
Use when building CLI tools, implementing argument parsing, or adding interactive prompts. Invoke for CLI design, argument parsing, interactive prompts, progress indicators, shell completions.
Publish local skills to ClawHub with customizable version, name, path, and optional changelog using command line or Python API.