Ship Safe
Comprehensive red-team scanner for the agentic era. Detects Claude-specific vulnerabilities including malicious hooks and insecure MCP transports.
CLI security scanner that runs 23 specialized agents in parallel — detecting secrets, SQL/command injection, SSRF, Docker/Kubernetes misconfigs, MCP tool injection, malicious Claude Code hooks, and RAG poisoning. An interactive fix agent shows a diff for each proposed change, asks before writing, and verifies the fix worked. Scanning works offline with no API key; an LLM provider is optional for AI-assisted analysis.
- Run a full security audit with HTML report before shipping to production
- Red-team your AI agent configuration with 80+ attack classes
- Detect malicious Claude Code hooks and insecure MCP transports
Comprehensive red-team scanner for the agentic era. Detects Claude-specific vulnerabilities including malicious hooks and insecure MCP transports.
Security-conscious development teams who want a comprehensive pre-deploy security audit.
https://github.com/asamassekou10/ship-safe
By asamassekou10
How to Get It
npx ship-safe
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
After installing, paste this into Claude:
Help me run a full security audit with HTML report before shipping to production
Trust Signals Auto-scanned
Community Pulse Active
Discussed on Hacker News, Reddit
- Iran to allow safe passage of Philippine ships, fuel supply through Strait of Ho — Reddit · 9119 pts
- Iran envoy confirms Tehran giving safe passage to Indian ships in Strait of Horm — Reddit · 8124 pts
- Ship safe 2025 — Reddit · 79 pts
3 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 744 GitHub stars; 1 contributors; last commit 51d ago; license MIT.
Things to check
- Recently discovered. Looks promising but has limited community feedback so far. We added it early so you can evaluate it before the crowd finds it.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 744 GitHub stars; 1 contributors; last commit 51d ago; license MIT.