Scan Any Repo
Before You Install
Paste a GitHub URL or a skill/config file. Get a security report in seconds. Review potential risks before you trust unfamiliar code.
This web scanner processes submissions on our server. Temporary files are deleted after processing. Keep private code and secrets on your machine with the local CLI.
Public repos only. Up to 15 MB compressed, 75 MB extracted, and 10,000 archive entries. Web scans are rate limited.
What We Scan
Six layers of security analysis
Malicious Code
postinstall scripts, obfuscated code, data exfiltration
Prompt Injection
CLAUDE.md manipulation, hidden instructions, override attempts
Hardcoded Secrets
API keys, tokens, credentials that shouldn't be in source
Vulnerable Dependencies
Known CVEs, deprecated packages, typosquatting
MCP Server Safety
Suspicious commands, curl|sh installs, env var leaks
Code Vulnerabilities
SQL injection, XSS, command injection, 1,000+ rules
Scan unlimited repos locally — free forever
Install the CLI and scan any GitHub repo, npm package, or MCP server in seconds.
npm install -g @shipsafe/clishipsafe audit https://github.com/user/repo