PluginBench
MCP Server

GhostFree MCP Server

io.github.shane-js/ghostfree

What is the GhostFree MCP server?

MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.

How to install GhostFree

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • GHOSTFREE_DIR

    Override the directory where GhostFree stores its data files (accepted-risks.yml, config.yml). Defaults to .ghostfree/ in the scanned repository root.

  • GHOSTFREE_MIN_SEVERITY

    Minimum CVE severity level to surface. One of: CRITICAL, HIGH, MEDIUM (default), LOW.

  • NVD_API_KEY
    secret

    Optional NVD API key for higher rate limits when enriching CVE details. Free to request at https://nvd.nist.gov/developers/request-an-api-key.

Claude Desktop
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "ghostfree": {
      "command": "npx",
      "args": [
        "-y",
        "ghostfree",
        "-y",
        "--repo-path"
      ],
      "env": {
        "GHOSTFREE_DIR": "<YOUR_GHOSTFREE_DIR>",
        "GHOSTFREE_MIN_SEVERITY": "<YOUR_GHOSTFREE_MIN_SEVERITY>",
        "NVD_API_KEY": "<YOUR_NVD_API_KEY>"
      }
    }
  }
}
Cursor
~/.cursor/mcp.json
{
  "mcpServers": {
    "ghostfree": {
      "command": "npx",
      "args": [
        "-y",
        "ghostfree",
        "-y",
        "--repo-path"
      ],
      "env": {
        "GHOSTFREE_DIR": "<YOUR_GHOSTFREE_DIR>",
        "GHOSTFREE_MIN_SEVERITY": "<YOUR_GHOSTFREE_MIN_SEVERITY>",
        "NVD_API_KEY": "<YOUR_NVD_API_KEY>"
      }
    }
  }
}
Windsurf
~/.codeium/windsurf/mcp_config.json
{
  "mcpServers": {
    "ghostfree": {
      "command": "npx",
      "args": [
        "-y",
        "ghostfree",
        "-y",
        "--repo-path"
      ],
      "env": {
        "GHOSTFREE_DIR": "<YOUR_GHOSTFREE_DIR>",
        "GHOSTFREE_MIN_SEVERITY": "<YOUR_GHOSTFREE_MIN_SEVERITY>",
        "NVD_API_KEY": "<YOUR_NVD_API_KEY>"
      }
    }
  }
}
VS Code
.vscode/mcp.json
{
  "servers": {
    "ghostfree": {
      "type": "stdio",
      "command": "npx",
      "args": [
        "-y",
        "ghostfree",
        "-y",
        "--repo-path"
      ],
      "env": {
        "GHOSTFREE_DIR": "<YOUR_GHOSTFREE_DIR>",
        "GHOSTFREE_MIN_SEVERITY": "<YOUR_GHOSTFREE_MIN_SEVERITY>",
        "NVD_API_KEY": "<YOUR_NVD_API_KEY>"
      }
    }
  }
}
Claude Code
claude mcp add ghostfree --env GHOSTFREE_DIR=<YOUR_GHOSTFREE_DIR> --env GHOSTFREE_MIN_SEVERITY=<YOUR_GHOSTFREE_MIN_SEVERITY> --env NVD_API_KEY=<YOUR_NVD_API_KEY> -- npx -y ghostfree -y --repo-path

Related MCP servers

Give your AI agent stealth web scraping with Cloudflare bypass and CSS selection, powered by Scrapling.

67k
Python
BSD-3-Clause
View repository →

Give your AI coding agent full control of a live Chrome browser for automation, debugging, and performance analysis.

45k
TypeScript
Apache-2.0
View repository →

Let AI agents manage your Puter files, websites, and serverless workers over MCP.

43k
TypeScript
AGPL-3.0
View repository →

Browser automation for AI agents via MCP, powering ByteDance's Agent TARS hybrid GUI/DOM browser control.

37k
TypeScript
Apache-2.0
View repository →

Run arbitrary shell commands from an MCP-connected AI agent.

37k
TypeScript
Apache-2.0
View repository →

Filesystem access MCP server from ByteDance's UI-TARS/Agent TARS ecosystem.

37k
TypeScript
Apache-2.0
View repository →