ship-safe — security grade SAFE, quality 73/100

Security audit verdict: SAFE · quality 73/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by asamassekou10 · MCP Server · ★ 830

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is ship-safe safe to install? View the security audit →

About ship-safe

AI-powered application security platform for developers. shipsafecli.com 18 security agents. 80+ attack classes. One command. Ship Safe v6.4.0 is an AI-powered security platform that runs 18 specialized agents in parallel against yo

agentic-aiai-securityclidevscopsllm-securitymcpnpmowaspsecretssecurity

Quick Facts

Stars830
Forks111
LanguageJavaScript
CategoryMCP Server
LicenseMIT
Quality Score73.4191581895072/100
Open Issues8
Last Updated2026-09-05
Created2026-02-02
Platformscli, mcp, node
Est. Tokens~20k

ship-safe alternative? Top 6 similar tools

Looking for a ship-safe alternative? If you're comparing ship-safe with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • agentic-radar by splx-ai · ⭐ 1.0k

    A security scanner for your LLM agentic workflows

  • agent-audit by HeadyZhang · ⭐ 211

    Static security scanner for LLM agents — prompt injection, MCP config auditing, taint analysis. 51 rules mappe

  • medusa by Pantheon-Security · ⭐ 962

    AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions

  • node9-proxy by node9-ai · ⭐ 210

    The Execution Security Layer for the Agentic Era. Providing deterministic "Sudo" governance and audit logs for

  • CyberStrike by CyberStrikeus · ⭐ 1.9k

    Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models,

  • onecli by onecli · ⭐ 3.5k

    Open-source sandboxed agent harness for teams. Giving every employee a secured personal agent.

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular JavaScript Agent Tools

Frequently Asked Questions

What is ship-safe?

ship-safe is CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.. It is categorized as a MCP Server with 830 GitHub stars.

What programming language is ship-safe written in?

ship-safe is primarily written in JavaScript. It covers topics such as agentic-ai, ai-security, cli.

How do I install or use ship-safe?

You can find installation instructions and usage details in the ship-safe GitHub repository at github.com/asamassekou10/ship-safe. The project has 830 stars and 111 forks, indicating an active community.

What license does ship-safe use?

ship-safe is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to ship-safe?

The top alternatives to ship-safe on Agent Skills Hub include agentic-radar, agent-audit, medusa. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools