OSV provides an open vulnerability database and API for querying vulnerabilities by package, version, commit, or vulnerability identifier.
Every capability is a discrete, logged action the agent calls by name — scoped to what you authorize and recorded in the run trace.