Ship Safe, an open source security scanner for coding agents
Ship Safe is a new open-source security scanner designed to help software teams identify vulnerabilities in AI agents, supply chains, and application code. It operates locally and provides tools for auditing, red-teaming, and applying safe fixes to codebases.
Why it matters
As AI agents become more integrated into software development, tools that secure these automated workflows are becoming critical for enterprise security.
Find risky code, AI-agent vulnerabilities, and supply-chain issues before they ship.
Website · Docs · Security & Data Flow · Benchmark · Pricing · Blog · Contribute
Ship Safe is an AI security scanner for modern software teams. It runs locally in your repo, finds issues across application code, AI agents, MCP configs, prompts, dependencies, CI/CD, secrets, and cloud-adjacent configuration, then helps you review and apply safe fixes.
npx ship-safe No signup. No API key required for scanning. Works offline for core checks. AI-backed red-team modes use your configured provider when available.
Use --no-ai to guarantee a fully local scan. Provider-backed classification, deep analysis, and GPT-Red send bounded context directly to your selected provider after best-effort credential masking. See Security & Data Flow for exact boundaries and context limits.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in