Findriskycode.Fix it before it ships.

Local scans, PR fixes, and cloud history when your team needs it.

0 stars0 downloadsMIT29 agents
Kimi K3 red-team demo3.5x
Built for stacks usingAnthropicOpenAIStripeVercelCursorSupabaseMCP

One security workflow.
Four clear steps.

Start with a local scan. Add deeper context and automation only when you need it.

01

Run it where you work.

Scan any repository from the terminal without creating an account or uploading the entire codebase.

$
  • One-command setup
  • Local-first scanning
  • CI-ready output
Run your first scan
Ship Safe CLI scanning a repository
02

See what matters first.

Move past a flat list of warnings. Ship Safe groups findings by severity, confidence, and real exploitability.

  • Prioritized findings
  • Security score
  • Clear remediation context
Ship Safe scan results ranked by risk
03

Stop risky changes before merge.

PR Guardian puts the finding, affected code, and fix guidance inside the review your team is already reading.

  • Pull-request checks
  • Inline fix guidance
  • Configurable release gates
Explore PR Guardian
Ship Safe PR Guardian configuration
04

Turn new threats into checks.

Security Intelligence connects advisories and exploit context to the technologies inside your stack.

  • Threat-informed coverage
  • Stack-aware relevance
  • Actionable checks
Agent team active

Give every security workflow its own team.

Compose specialized Hermes agents for deploy checks, investigation, monitoring, and incident response. You define the playbook; Ship Safe coordinates the work.

  1. 01DelegateRoute work to the right specialist.
  2. 02InvestigateShare context without losing control.
  3. 03RespondReturn one prioritized action plan.
Explore Hermes agent teams

Test your AI agents like an attacker.

Use Kimi K3-powered adversarial analysis to probe tool calls, long-context behavior, and agent boundaries.

$
See how Kimi K3 works
Ship Safe and Kimi K3 AI red-team workflow

Your first report is one command away.

$

No account required for local scans.

Start free. Upgrade when the workflow grows.

The scanner stays free. Pro adds the hosted tools that help teams keep moving.

Free CLI$0

Unlimited local scans and CI-ready security output.

Run locally
Pro$9/month

Hosted history, private repos, reports, and PR Guardian.

Start Pro
Compare every plan and feature

Know before you scan.

Does Ship Safe work without an API key?
Yes. Core scans run locally without an API key. AI-backed analysis is optional and can be skipped with --no-ai.
Is my code sent to an LLM?
Only in provider-backed modes. Use --no-ai to keep scanning fully local. See the security and data-flow details.
Is the CLI free?
Yes. The CLI is MIT open-source and free for local scans. Paid plans add hosted history, private repositories, PR checks, and reports.

Help build security for AI-assisted development.

Ship Safe is MIT open source. Add agents, MCP rules, fixtures, docs, CI examples, and dashboard improvements with a focused contributor path.

Find the risk before users do.

Run locally for free, then add the cloud when your team needs history and automation.

$