BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Ship Safe

Skill Security Solid
Works inClaude Code
Solid Scanned — metadata only

Comprehensive red-team scanner for the agentic era. Detects Claude-specific vulnerabilities including malicious hooks and insecure MCP transports.

CLI security scanner that runs 23 specialized agents in parallel — detecting secrets, SQL/command injection, SSRF, Docker/Kubernetes misconfigs, MCP tool injection, malicious Claude Code hooks, and RAG poisoning. An interactive fix agent shows a diff for each proposed change, asks before writing, and verifies the fix worked. Scanning works offline with no API key; an LLM provider is optional for AI-assisted analysis.

773 starsMIT (commercial OK)FreeQuick setup

Comprehensive red-team scanner for the agentic era. Detects Claude-specific vulnerabilities including malicious hooks and insecure MCP transports.

Security-conscious development teams who want a comprehensive pre-deploy security audit.

Claude Code Claude Cowork Claude Chat

https://github.com/asamassekou10/ship-safe

By asamassekou10

How to Get It

Option 1: Claude Desktop App (Code Mode)Click the + button next to the prompt box → PluginsAdd plugin. Search and click Install. Skills work in Claude Code only.
Option 2: Paste into Claude CodeCopy the command below and paste it into your conversation. Claude will install it.
Command
npx ship-safe

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

After installing, paste this into Claude:

Help me run a full security audit with HTML report before shipping to production
PrerequisitesNode.js (runs via npx). No API key required for scanning; optional LLM provider (Anthropic, OpenAI, Ollama, and others) for AI features.Time to functional< 5 minutesCostFree

Trust Signals Auto-scanned

Stars773Contributors2Last updated2026-08-01LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-01 · scanner v1

Community Pulse Active

Discussed on Hacker News, Reddit

3 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 744 GitHub stars; 1 contributors; last commit 51d ago; license MIT.

Things to check

  • Recently discovered. Looks promising but has limited community feedback so far. We added it early so you can evaluate it before the crowd finds it.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
4/5
Versatility
4/5
Reliability
3/5
Security
4/5
Overall score3.75 / 5.00 SolidEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 744 GitHub stars; 1 contributors; last commit 51d ago; license MIT.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →