Live — scan repos, skills, and configs

Scan Any Repo Before You Install

Paste a GitHub URL or a skill/config file. Get a security report in seconds. Know if it's safe before it touches your machine.

Public repos only. Rate limited to 5 scans per 10 minutes.

What We Scan

Six layers of security analysis

Malicious Code

postinstall scripts, obfuscated code, data exfiltration

Prompt Injection

CLAUDE.md manipulation, hidden instructions, override attempts

Hardcoded Secrets

API keys, tokens, credentials that shouldn't be in source

Vulnerable Dependencies

Known CVEs, deprecated packages, typosquatting

MCP Server Safety

Suspicious commands, curl|sh installs, env var leaks

Code Vulnerabilities

SQL injection, XSS, command injection, 1,000+ rules

Scan unlimited repos locally — free forever

Install the CLI and scan any GitHub repo, npm package, or MCP server in seconds.

$npm install -g @shipsafe/cli
$shipsafe audit https://github.com/user/repo