MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.
io.github.shane-js/ghostfree
https://github.com/shane-js/ghostfree#readme
STDIO
No auth required
Hosted endpoint — paste into any MCP client.
Configuration this server reads at startup.
Override the directory where GhostFree stores its data files (accepted-risks.yml, config.yml). Defaults to .ghostfree/ in the scanned repository root.
Minimum CVE severity level to surface. One of: CRITICAL, HIGH, MEDIUM (default), LOW.
Optional NVD API key for higher rate limits when enriching CVE details. Free to request at https://nvd.nist.gov/developers/request-an-api-key.
Where to find authoritative docs and source for GhostFree.
Open MCP Agent Studio and connect this server to Claude, GPT, Gemini, DeepSeek and more — no install required.
Open Agent Studio