MCPLow riskUnclaimed

GhostFree

MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.

shane-jsshane-js/ghostfree★ 1Updated Apr 7, 2026

server.json

{
  "$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
  "name": "io.github.shane-js/ghostfree",
  "description": "MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.",
  "title": "GhostFree",
  "repository": {
    "url": "https://github.com/shane-js/ghostfree",
    "source": "github"
  },
  "version": "0.2.0",
  "websiteUrl": "https://github.com/shane-js/ghostfree#readme",
  "icons": [
    {
      "src": "https://raw.githubusercontent.com/shane-js/ghostfree/main/icon.png",
      "mimeType": "image/png",
      "sizes": [
        "512x512"
      ]
    }
  ],
  "packages": [
    {
      "registryType": "npm",
      "identifier": "ghostfree",
      "version": "0.2.0",
      "runtimeHint": "npx",
      "transport": {
        "type": "stdio"
      },
      "runtimeArguments": [
        {
          "value": "-y",
          "type": "positional"
        }
      ],
      "packageArguments": [
        {
          "description": "Absolute path to the repository to scan for vulnerable dependencies.",
          "isRequired": true,
          "format": "filepath",
          "type": "named",
          "name": "--repo-path"
        }
      ],
      "environmentVariables": [
        {
          "description": "Override the directory where GhostFree stores its data files (accepted-risks.yml, config.yml). Defaults to .ghostfree/ in the scanned repository root.",
          "format": "filepath",
          "name": "GHOSTFREE_DIR"
        },
        {
          "description": "Minimum CVE severity level to surface. One of: CRITICAL, HIGH, MEDIUM (default), LOW.",
          "format": "string",
          "default": "MEDIUM",
          "choices": [
            "CRITICAL",
            "HIGH",
            "MEDIUM",
            "LOW"
          ],
          "name": "GHOSTFREE_MIN_SEVERITY"
        },
        {
          "description": "Optional NVD API key for higher rate limits when enriching CVE details. Free to request at https://nvd.nist.gov/developers/request-an-api-key.",
          "format": "string",
          "isSecret": true,
          "name": "NVD_API_KEY"
        }
      ]
    }
  ]
}

Permissions

DeclaredDetected
Runs code—node
Installs—npm:ghostfree@0.2.0
Runs install scripts—None
NetworkNoneNone
Needs credentialsNVD_API_KEYNVD_API_KEY
Outside the workspace—None
Agent tools—None

Checks

Low risk · Nothing worth a warning was found.

Not reviewed by a person · Checked by rules; the model review is not switched on yet.

Versions

  1. #10.2.0latestOct 7, 2026