Skip to content
mcp/skillhub

GhostFree MCP Server

by shane-jsio.github.shane-js/ghostfreev0.2.0

MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.

1Node.jsstdioofficial registry

context tax

queued

security

queued

cold start

queued

freshness

Stale6mo ago

Install GhostFree MCP server

Install in Claude Code

claude mcp add ghostfree -e NVD_API_KEY='<nvd-api-key>' -- npx -y ghostfree --repo-path '<--repo-path>'

Configuration

VariableRequiredSecretDescription
GHOSTFREE_DIR——Override the directory where GhostFree stores its data files (accepted-risks.yml, config.yml). Defaults to .ghostfree/ in the scanned repository root.
GHOSTFREE_MIN_SEVERITY——Minimum CVE severity level to surface. One of: CRITICAL, HIGH, MEDIUM (default), LOW.
NVD_API_KEY—yesOptional NVD API key for higher rate limits when enriching CVE details. Free to request at https://nvd.nist.gov/developers/request-an-api-key.

Freshness

Stale — last maintenance signal 6mo ago. The newest of the signals below sets the band.

  1. Last commit (default branch)

    2026-04-07 · 6mo ago · GitHub

  2. Latest release

    2026-04-06 · 6mo ago · GitHub · v0.2.0

  3. Package published

    no data · npm/PyPI

  4. Registry entry updated

    2026-04-07 · 6mo ago · official registry · v0.2.0

FAQ

›How do I install the GhostFree MCP server in Claude Code?

Run: claude mcp add ghostfree -e NVD_API_KEY='<nvd-api-key>' -- npx -y ghostfree --repo-path '<--repo-path>'. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.

›Does GhostFree require an API key?

Yes. It expects NVD_API_KEY, of which 1 is a secret.

›Can I use GhostFree as a remote (hosted) MCP server?

No hosted endpoint is published; it runs locally over stdio.

›Is GhostFree in the official MCP registry?

Yes, as io.github.shane-js/ghostfree.

Alternatives to GhostFree

Other security MCP servers.

View all