Shipcheck

Shipcheck

Local CLI that scans JS/TS and MCP repos for launch risks and sensitive metadata.

Free - Free to run via npx (e.g., npx --yes shipcheck-cli .) with no account required.

Visit Website

About Shipcheck

Shipcheck is a command-line scanner for JavaScript, TypeScript, and MCP repositories that checks for launch risks and sensitive signals before shipping. It detects environment-boundary issues, Stripe webhook exposure, Supabase/Firebase evidence, debug or admin routes, dependency hygiene and npm trusted-publishing drift, MCP smoke-test proof, STDIO execution boundaries, remote auth notes, and registry metadata. Run locally via npx to get a fast pre-launch risk report.

Key Features

  • Local CLI scan of JS/TS and MCP repos via npx
  • Detects env boundary issues, debug routes, and remote auth notes
  • Finds Stripe webhook exposure and Supabase/Firebase evidence
  • Audits dependency hygiene and npm trusted-publishing drift
  • Checks MCP smoke-test proof, STDIO execution boundaries, and registry metadata

Who is this for?

Developers, DevOps/SREs, and security engineers preparing repositories for launch

Comments (0)

No comments yet

Be the first to share your thoughts!

Sign in to join the conversation

Sign In