{"repo":"asamassekou10/ship-safe","free":true,"listed":false,"github":"https://github.com/asamassekou10/ship-safe","clone":"git clone https://github.com/asamassekou10/ship-safe.git","description":"CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.","language":"JavaScript","stars":824,"topics":["cli","devscops","npm","owasp","secrets","security","security-tools","static-analysis","agentic-ai","ai-security"],"license":"MIT","category":"security-tools","readme_excerpt":"Find risky code, AI-agent vulnerabilities, and supply-chain issues before they ship. Website · Docs · Security & Data Flow · Benchmark · Pricing · Blog · Contribute Ship Safe CLI Ship Safe is an AI security scanner for modern software teams. It runs locally in your repo, finds issues across application code, AI agents, MCP configs, prompts, dependencies, CI/CD, secrets, and cloud-adjacent configuration, then helps you review and apply safe fixes. Start a scan with one command: No signup. No API key required for scanning. Works offline for core checks. AI-backed red-team modes use your configured provider when available. Use --no-ai to guarantee a fully local scan. Provider-backed classification, deep analysis, and GPT-Red send bounded context directly to your selected provider after best-effort credential masking. See Security & Data Flow for exact boundaries and context limits. --- Quick Start What Ship Safe Finds Area Examples ------ ---------- AI and LLM security Prompt injection, agent hijacking, excessive agency, memory poisoning, RAG poisoning, unsafe tool calls MCP and agent configs Over-broad tool permissions, poisoned registries, untrusted transports, dangerous allowlists Application security SQL/NoSQL injection, XSS, SSRF, auth bypass, path traversal, insecure API routes Secrets and compliance API keys, tokens, credentials, PII, leaked secrets in git history Supply chain Typosquatting, dependency confusion, risky install scripts, unpinned AI actions CI/CD Pipeline p","default_branch":null,"files":null,"tree":[],"storefront":"/r/asamassekou10","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/asamassekou10/ship-safe/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}