GhostFree MCP Server
by shane-jsio.github.shane-js/ghostfreev0.2.0
MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.
context tax
queued
security
queued
cold start
queued
freshness
Stale6mo ago
Install GhostFree MCP server
Install in Claude Code
claude mcp add ghostfree -e NVD_API_KEY='<nvd-api-key>' -- npx -y ghostfree --repo-path '<--repo-path>'Install in Cursor
{
"mcpServers": {
"ghostfree": {
"command": "npx",
"args": [
"-y",
"ghostfree",
"--repo-path",
"<--repo-path>"
],
"env": {
"NVD_API_KEY": "<nvd-api-key>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"ghostfree": {
"command": "npx",
"args": [
"-y",
"ghostfree",
"--repo-path",
"<--repo-path>"
],
"env": {
"NVD_API_KEY": "<nvd-api-key>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"ghostfree": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"ghostfree",
"--repo-path",
"<--repo-path>"
],
"env": {
"NVD_API_KEY": "<nvd-api-key>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"ghostfree": {
"command": "npx",
"args": [
"-y",
"ghostfree",
"--repo-path",
"<--repo-path>"
],
"env": {
"NVD_API_KEY": "<nvd-api-key>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| GHOSTFREE_DIR | — | — | Override the directory where GhostFree stores its data files (accepted-risks.yml, config.yml). Defaults to .ghostfree/ in the scanned repository root. |
| GHOSTFREE_MIN_SEVERITY | — | — | Minimum CVE severity level to surface. One of: CRITICAL, HIGH, MEDIUM (default), LOW. |
| NVD_API_KEY | — | yes | Optional NVD API key for higher rate limits when enriching CVE details. Free to request at https://nvd.nist.gov/developers/request-an-api-key. |
Freshness
Stale — last maintenance signal 6mo ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-04-07 · 6mo ago · GitHub
Latest release
2026-04-06 · 6mo ago · GitHub · v0.2.0
Package published
no data · npm/PyPI
Registry entry updated
2026-04-07 · 6mo ago · official registry · v0.2.0
FAQ
›How do I install the GhostFree MCP server in Claude Code?
Run: claude mcp add ghostfree -e NVD_API_KEY='<nvd-api-key>' -- npx -y ghostfree --repo-path '<--repo-path>'. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does GhostFree require an API key?
Yes. It expects NVD_API_KEY, of which 1 is a secret.
›Can I use GhostFree as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is GhostFree in the official MCP registry?
Yes, as io.github.shane-js/ghostfree.
Alternatives to GhostFree
Other security MCP servers.