What this skill does
Scans Node.js/NPM and Linux packages for known vulnerabilities using the Google OSV API by analyzing dependencies and reporting related CVEs.
OSV Scanner is part of the Research & Knowledge category — research and knowledge skills that gather, search, and summarize information. You can install it on its own or alongside other research & knowledge skills from the OpenClaw catalog.
How to install OSV Scanner
The easiest path is via the OpenClaw Easy desktop app — one click, no terminal required:
- Download OpenClaw Easy for macOS or Windows (free, one-click installer, ~30 seconds).
- Open the in-app Skills panel.
- Search for
osv-scannerand click Install. - The skill activates automatically when an incoming message matches its description.
Install from the command line
If you already run the OpenClaw CLI, add OSV Scanner with a single command:
openclaw skills add osv-scanner
This pulls osv-scanner from ClawHub and installs it into ~/.openclaw/skills/osv-scanner/. Restart the OpenClaw gateway afterwards so the new skill is discovered.
How to use OSV Scanner
Once installed, OSV Scanner activates on its own: when an incoming message on WhatsApp, Telegram, Slack, Discord, Feishu or Line matches the skill's description, your OpenClaw agent loads it and runs the workflow. You can also trigger it explicitly by describing the task in chat. No extra configuration is required after install.
Manual install (advanced)
If you prefer manual installation:
- Click the Download .zip button above to grab
osv-scanner-1.0.0.zipdirectly from our S3 mirror. - Unzip into
~/.openclaw/skills/osv-scanner/(create the directory if it does not exist). - Restart OpenClaw Easy (or the OpenClaw CLI gateway) so the new skill is discovered.
Frequently asked questions
How do I install OSV Scanner?
Install OSV Scanner in the OpenClaw Easy desktop app by opening the Skills panel, searching for osv-scanner, and clicking Install. From a terminal you can run: openclaw skills add osv-scanner. Either way the skill is placed in ~/.openclaw/skills/osv-scanner/.
Is OSV Scanner free?
Yes. OSV Scanner is free and open-source, distributed under the Apache-2.0 license through ClawHub. No account or payment is required to download or run it.
What does OSV Scanner do?
Scans Node.js/NPM and Linux packages for known vulnerabilities using the Google OSV API by analyzing dependencies and reporting related CVEs.
Related: more research & knowledge skills
If OSV Scanner looks useful, you may also want to check out other research & knowledge skills in the OpenClaw catalog:
Browse the full OpenClaw skill catalog
This page covers just one skill. The OpenClaw skill hub has 10,000+ more — search, sort by downloads or stars, and install any of them in one click. There is also a curated awesome-openclaw-skills list grouped by use case.
Get OpenClaw Easy — Free
Install OSV Scanner and 10,000+ other OpenClaw skills in one click. Free, open-source, runs locally on macOS & Windows.
Free, open-source · Apache-2.0 · Works with Claude, ChatGPT, Gemini, or local Ollama models