Article URL: https://github.com/asamassekou10/ship-safe Comments URL: https://news.ycombinator.com/item?id=49192277 Points: 5 # Comments: 5

Find risky code, AI-agent vulnerabilities, and supply-chain issues before they ship. Ship Safe is an AI security scanner for modern software teams. It runs locally in your repo, finds issues across application code, AI agents, MCP configs, prompts, dependencies, CI/CD, secrets, and cloud-adjacent configuration, then helps you review and apply safe fixes. No signup. No API key required for scanning. Works offline for core checks. AI-backed red-team modes use your configured provider when available. Use --no-ai to guarantee a fully local scan. Provider-backed classification, deep analysis, and GPT-Red send bounded context directly to your selected provider after best-effort credential masking. See Security & Data Flow for exact boundaries and context limits. The open-source CLI is the fastest way to scan any repo locally. Upgrade when you need a hosted workflow around the same scanner: Ship Safe Cloud, the hosted dashboard for scan history, PR Guardian, billing, and team workflows, is developed in a private repository because it contains commercial product code and hosted infrastructure workflows. The public ship-safe repo remains focused on the MIT-licensed CLI, security agents, rules, fixtures, CI integrations, and documentation. See Ship Safe Cloud for the repo boundary. Post-processors: ScoringEngine · VerifierAgent (secrets liveness) · DeepAnalyzer (LLM taint analysis) Anything not starting with / is sent to the LLM as a free-form question, with your latest scan results as context.