Live — scan repos, skills, and configs
Scan Any Repo
Before You Install
Paste a GitHub URL or a skill/config file. Get a security report in seconds. Know if it's safe before it touches your machine.
Public repos only. Rate limited to 5 scans per 10 minutes.
What We Scan
Six layers of security analysis
Malicious Code
postinstall scripts, obfuscated code, data exfiltration
Prompt Injection
CLAUDE.md manipulation, hidden instructions, override attempts
Hardcoded Secrets
API keys, tokens, credentials that shouldn't be in source
Vulnerable Dependencies
Known CVEs, deprecated packages, typosquatting
MCP Server Safety
Suspicious commands, curl|sh installs, env var leaks
Code Vulnerabilities
SQL injection, XSS, command injection, 1,000+ rules
Scan unlimited repos locally — free forever
Install the CLI and scan any GitHub repo, npm package, or MCP server in seconds.
$
npm install -g @shipsafe/cli$
shipsafe audit https://github.com/user/repo