Developer · Local MCP server

GhostFree

MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.

Visit GhostFree's website

What the MCP Registry states

The entry as published to the official MCP Registry (read 2026-10-04), latest version.

Registry name
io.github.shane-js/ghostfree
Version
0.2.0
Status
Active
Category
developer
Transport
stdio (local process)
Package
npm
Published
2026-04-07
Updated
2026-04-07
Publisher
shane-js (GitHub)
Website
github.com/shane-js/ghostfree#readme
Repository
github.com/shane-js/ghostfree
Source
Registry API entry

Packages

RegistryPackageVersionTransportEnvironment variables
npmruntime: npxghostfree0.2.0stdioGHOSTFREE_DIR, GHOSTFREE_MIN_SEVERITY, NVD_API_KEY (secret)

How to connect GhostFree

GhostFree runs locally from a Node.js package published to the npm registry: ghostfree version 0.2.0. It speaks MCP over stdio, so the client starts it as a program and talks to it through standard input and output. It needs Node.js; clients usually start it with npx — the usual command is npx -y ghostfree@0.2.0. It reads these environment variables: GHOSTFREE_DIR, GHOSTFREE_MIN_SEVERITY and NVD_API_KEY (secret); set them in the client's configuration for this server. Required arguments: --repo-path.

In the mcpServers JSON format that many desktop and editor MCP clients read, the entry looks like this (placeholders in angle brackets):

{
  "mcpServers": {
    "ghostfree": {
      "command": "npx",
      "args": [
        "-y",
        "ghostfree@0.2.0"
      ],
      "env": {
        "GHOSTFREE_DIR": "<value>",
        "GHOSTFREE_MIN_SEVERITY": "<value>",
        "NVD_API_KEY": "<secret>"
      }
    }
  }
}

Derived from the registry entry, not tested here. What the server does, and on what terms, is set by its publisher; check its repository or website before giving it access to your accounts or files. How to add an MCP server to an assistant · Before you connect

More developer servers

All 6,250 →
ServerRunsEndpoint or package
Ghidra Retro MCPHeadless Ghidra MCP server with P-code emulation and multi-console ROM triage.Local · stdioPyPI: ghidra-retro-mcp
Ghost in the DroidGive any LLM agent a real Android or iPhone as its body. 62 MCP tools for mobile automation.Local · stdioPyPI: ghost-in-the-droid
Ghost Inspector MCPAnalyze, validate and safely update Ghost Inspector end-to-end browser tests.Local · stdionpm: ghost-inspector-mcp
GhostfoxSelf-hosted stealth browser for AI agents: Firefox engine + Rust MCP runtime.Local · stdioPyPI: ghostfox
GhostlightVisible local browser automation in signed-in Chromium, with optional policy and audit.Local · stdionpm: ghostlight
GhostlinkSandboxed repo access for coding agents: search, read, patch, run, git -- confined to a repo root.Local · stdionpm: @bgorzelic/ghostlink
gigachat-mcpMCP server for GigaChat — AI chat, embeddings, image generation (Russia)Local · stdionpm: @theyahia/gigachat-mcp
gildara.ioOperating contracts for AI agents. Structured instructions compiled into system prompts.Local · stdionpm: @gildara/mcp-server