Ship Safe: An Open Source Security Scanner for AI Coding Agents
Ship Safe, an open source security scanner for coding agents
Ship Safe is a free, open-source CLI that scans your repository for security issues introduced by AI coding agents. It detects CI/CD misconfigurations, over-permissive agent permissions, MCP tool injection, hardcoded secrets, and even DMCA-flagged AI dependencies. Run it locally with a single command, no signup or API key required, and get actionable findings with severity ratings and suggested fixes. The tool also offers an interactive REPL, CI/CD integration, and supports a wide range of LLM providers for AI-assisted analysis.
Ship Safe covers a narrower question: what an AI coding agent just did to your repository, your CI, and your local tool configuration.