GhostFree
About
MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.
Use this server
Add it to your MCP client. The catalogue lists this config verbatim from its source — it does not run, download, or vouch for the server. Review the command before you run it.
Transportstdio (runs a local command)
Env vars
GHOSTFREE_DIR GHOSTFREE_MIN_SEVERITY NVD_API_KEYClaude Code
claude mcp add --env GHOSTFREE_DIR= --env GHOSTFREE_MIN_SEVERITY= --env NVD_API_KEY= ghostfree -- npx ghostfree
Cursor
If the button doesn't open Cursor, use the JSON below — Cursor accepts the same mcpServers config.
VS Code
code --add-mcp '{"name":"ghostfree","command":"npx","args":["ghostfree"],"env":{"GHOSTFREE_DIR":"","GHOSTFREE_MIN_SEVERITY":"","NVD_API_KEY":""}}'
JSON
{
"mcpServers": {
"ghostfree": {
"command": "npx",
"args": [
"ghostfree"
],
"env": {
"GHOSTFREE_DIR": "",
"GHOSTFREE_MIN_SEVERITY": "",
"NVD_API_KEY": ""
}
}
}
}
Environment variables are listed by name only — fill in your own values. Entries never carry secrets.