Ship Safe, an open source security scanner for coding agents
Ship Safe is an open‑source AI‑powered security scanner that runs locally to detect vulnerabilities in code, AI agents, configurations, dependencies, secrets, and CI/CD pipelines. The CLI provides interactive remediation, supports offline scans, and can be integrated into CI to fail builds on critical findings. A paid cloud service adds dashboard, team collaboration, and hosted workflow features while the core scanner remains MIT‑licensed.
- ▪Ship Safe scans repositories locally using a range of agents that identify issues such as prompt injection, insecure tool calls, and supply‑chain risks.
- ▪The tool offers an interactive REPL for fixing findings, supports CI integration with SARIF output, and can operate fully offline with the --no‑ai flag.
- ▪The open‑source CLI is free under an MIT license, while a commercial cloud offering provides scan history, PR guarding, and team collaboration features.
- ▪Ship Safe supports multiple languages and configuration formats, including JavaScript, TypeScript, Python, and infrastructure as code files.
- ▪Pricing includes a free tier for the CLI and paid plans for cloud dashboards and shared workspace capabilities.
Hacker News (Front Page) files mainly under programming. We currently carry 1,166 of its stories. Top-voted stories on Hacker News.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Story provenance
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | GitHub |
| Canonical URL | https://github.com/asamassekou10/ship-safe |
| Publication time | Thu, 06 Aug 2026 04:02:28 +0000 |
| Retrieval time | 2026-08-06T06:05:42.735Z |
| Last seen | 2026-08-06T06:05:42.735Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | PBwNC725H88_ · 1 stories |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
Find risky code, AI-agent vulnerabilities, and supply-chain issues before they ship. Website · Docs · Security & Data Flow · Benchmark · Pricing · Blog · Contribute Ship Safe CLI Ship Safe is an AI security scanner for modern software teams. It runs locally in your repo, finds issues across application code, AI agents, MCP configs, prompts, dependencies, CI/CD, secrets, and cloud-adjacent configuration, then helps you review and apply safe fixes. Start a scan with one command: npx ship-safe No signup. No API key required for scanning. Works offline for core checks. AI-backed red-team modes use your configured provider when available. Use --no-ai to guarantee a fully local scan.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at GitHub.