GhostFree
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| prompts | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| discover_dependenciesA | Scan the repository for manifest files (requirements.txt, package.json, go.mod, Cargo.toml, pom.xml, *.csproj, Dockerfiles, etc.) and return all pinned dependencies grouped by ecosystem. |
| check_cves | Check a list of packages against OSV.dev for known vulnerabilities. Returns CVEs above the severity threshold as a numbered list, suppressed/accepted risks, expired acceptances, and a count of below-threshold findings. |
| enrich_cve | Fetch enrichment data for a specific CVE ID: CVSS vectors and score from NVD, CWE weakness classification, references, and whether it appears in the CISA Known Exploited Vulnerabilities (KEV) catalog. Gracefully degrades if NVD or KEV are unavailable. |
| list_accepted_risks | List all accepted CVE risks, including whether each acceptance has expired. |
| accept_risk | Record an accepted risk for a CVE, with a reason and mandatory expiry date. Expiry beyond 1 year requires confirm_extended_expiry=true. |
| remove_accepted_risk | Remove a previously accepted risk by its UUID acceptance ID. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| scan | Run a full dependency vulnerability scan: discover packages, check OSV.dev for CVEs, triage with NVD/KEV enrichment, and get remediation guidance. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 1 tool
There is only one tool, so there is no possibility of confusion with other tools. The tool's purpose is clearly defined.
With a single tool, naming consistency is not an issue. The tool name 'discover_dependencies' follows a clear verb_noun pattern.
A single tool for dependency scanning is on the lower end of the scale. While it may be sufficient for basic discovery, the server would benefit from additional tools for other operations.
The server only offers dependency discovery, lacking any functionality for managing or removing dependencies. The name 'GhostFree' suggests a broader scope, making this toolset feel incomplete.