← Back to browse

GhostFree

Indexed by io.github.shane-js

About

MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.

Use this server

Add it to your MCP client. The catalogue lists this config verbatim from its source — it does not run, download, or vouch for the server. Review the command before you run it.

Transportstdio (runs a local command)
Env varsGHOSTFREE_DIR GHOSTFREE_MIN_SEVERITY NVD_API_KEY
Claude Code
claude mcp add --env GHOSTFREE_DIR= --env GHOSTFREE_MIN_SEVERITY= --env NVD_API_KEY= ghostfree -- npx ghostfree
Cursor

Add to Cursor

If the button doesn't open Cursor, use the JSON below — Cursor accepts the same mcpServers config.

VS Code
code --add-mcp '{"name":"ghostfree","command":"npx","args":["ghostfree"],"env":{"GHOSTFREE_DIR":"","GHOSTFREE_MIN_SEVERITY":"","NVD_API_KEY":""}}'
JSON
{
  "mcpServers": {
    "ghostfree": {
      "command": "npx",
      "args": [
        "ghostfree"
      ],
      "env": {
        "GHOSTFREE_DIR": "",
        "GHOSTFREE_MIN_SEVERITY": "",
        "NVD_API_KEY": ""
      }
    }
  }
}

Environment variables are listed by name only — fill in your own values. Entries never carry secrets.