#124 · Primary category: Cybersecurity & Decryption Tools

ship-safe

agentic-ai ai-security cli devscops llm-security mcp npm owasp secrets security security-tools static-analysis

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.

Project last updated:08/29/26

GitHub Stars

828

Forks

111

Contributors

16

License

MIT

Why we included this project

Once you wire AI agents, MCP servers, and LLM-backed tooling into a pipeline, the usual secret scanners stop being enough. Ship Safe is a local CLI that checks a repository for CI/CD misconfigurations, over-broad agent permissions, MCP tool injection, hardcoded secrets, and dependencies flagged for DMCA issues, then walks you through applying fixes. It runs with a single npx command, works offline for core checks, and only sends bounded context to a provider when you opt into its AI-backed red-team modes. That makes it a practical pre-commit or pre-deploy gate for small teams that want agentic workflows without losing sight of what those agents can actually touch.

Articles for this project

No articles for this project yet.

To suggest a topic or contribute an article, contact us.

Related projects in this category