ship-safe
View on GitHubThe independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic core, no API key needed, JSON and SARIF output.
CLI security scanner for AI-written software. A deterministic engine flags issues across app code, agents, MCP configs, prompts, deps, CI/CD and secrets, then an investigation layer confirms or refutes each finding with cited evidence in JSON/SARIF.
Use Cases
Scan AI-written code for security flawsDetect prompt injection and agent hijacking risksAudit MCP server and agent config permissionsFind leaked secrets and API keys in reposGate CI/CD pipelines on confirmed findings via SARIFRed-team agent-readable contentCheck dependency and supply chain securityGenerate reviewable fix diffs and PRs
Built With
- Language
- JavaScript
- Frameworks
- Node.js · MCP · GitHub Actions · SARIF · ESLint · Docker
Tags
ai-security · agent-security · llm-security · prompt-injection · mcp-security · sast · secrets-scanning · sarif · cli · devsecops · supply-chain-security · static-analysis · ci-cd-security · owasp · red-team · vulnerability-scanner