Live — scan repos, skills, and configs

Scan Any Repo Before You Install

Paste a GitHub URL or a skill/config file. Get a security report in seconds. Review potential risks before you trust unfamiliar code.

This web scanner processes submissions on our server. Temporary files are deleted after processing. Keep private code and secrets on your machine with the local CLI.

Public repos only. Up to 15 MB compressed, 75 MB extracted, and 10,000 archive entries. Web scans are rate limited.

What We Scan

Six layers of security analysis

Malicious Code

postinstall scripts, obfuscated code, data exfiltration

Prompt Injection

CLAUDE.md manipulation, hidden instructions, override attempts

Hardcoded Secrets

API keys, tokens, credentials that shouldn't be in source

Vulnerable Dependencies

Known CVEs, deprecated packages, typosquatting

MCP Server Safety

Suspicious commands, curl|sh installs, env var leaks

Code Vulnerabilities

SQL injection, XSS, command injection, 1,000+ rules

Scan unlimited repos locally — free forever

Install the CLI and scan any GitHub repo, npm package, or MCP server in seconds.

$npm install -g @shipsafe/cli
$shipsafe audit https://github.com/user/repo