About this integration
MCP server that scans your repo's dependencies for security vulnerabilities based on published CVEs.
- Transport
- stdio
- Authentication
- none
- Initial setup
- none
- Runtime
- unattended
- Evidence
- documented
- Version
- 0.2.0
- Package
- ghostfree
- Last compatibility test
- Not independently tested
Connect your agent
ghostfreePublisher documentation and manifest were reviewed; the package and vulnerability services were not executed. Scans require OSV network access. NVD authentication is optional for higher rate limits, and accepted-risk tools write to a repository-local file.
Capabilities: Discover dependencies across supported project manifests, Check packages against OSV vulnerability data, Enrich CVEs with NVD and CISA KEV data, Record expiring accepted-risk decisions
Connected profiles
Additional details
io.github.shane-js/ghostfree
Source ↗ · Checked 2026-09-170.2.0
Source ↗ · Checked 2026-09-17CC0-1.0; package licenses are separate
Source ↗ · Checked 2026-09-17npm
Source ↗ · Checked 2026-09-17ghostfree
Source ↗ · Checked 2026-09-190.2.0
Source ↗ · Checked 2026-09-19The publisher provides explicit stdio MCP configurations that launch the package with a repository path.
Source ↗ · Checked 2026-09-19OSV requires no authentication and NVD works at a lower rate without an optional API key.
Source ↗ · Checked 2026-09-19Configure the MCP client to launch npx -y ghostfree with --repo-path for the target repository.
Source ↗ · Checked 2026-09-19Publisher documentation reviewed; package and integration endpoint not executed or independently security-audited.
Source ↗ · Checked 2026-09-19