Skip to main content
ClaudeWave

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.

Subagents829 stars110 forksJavaScriptMITUpdated yesterday
ClaudeWave Trust Score
97/100
Verified
Passed
  • Open-source license (MIT)
  • Actively maintained (<30d)
  • Healthy fork ratio
  • Clear description
  • Topics declared
Last scanned: 9/3/2026
Install as a Claude Code subagent
Method: Clone
Terminal
git clone https://github.com/asamassekou10/ship-safe && cp ship-safe/*.md ~/.claude/agents/
1. Clone the repository and copy the agent .md definitions into ~/.claude/agents (or .claude/agents inside a project).
2. Start a new Claude Code session to load the agents.
3. Delegate work to them with the Task/Agent tool or by name.

9 items in this repository

Manage your security baseline — accept current findings as known debt, then only report new regressions on future scans. Use when the user wants to adopt security scanning incrementally or suppress existing findings.

Install

Run Ship Safe in CI mode — compact output, exit codes, SARIF generation. Use when the user wants to set up CI/CD security gates or test their pipeline configuration.

Install

Run a deep security audit with LLM-powered taint analysis — regex scan nominates findings, then an LLM verifies taint reachability and exploitability. Use when the user wants thorough, high-confidence results with fewer false positives.

Install

Auto-fix security issues — remediate hardcoded secrets and common vulnerabilities (TLS bypass, debug mode, XSS, shell injection, Docker :latest). Use when the user wants to automatically fix security findings.

Install

Install ship-safe as real-time Claude Code hooks — blocks secrets and dangerous commands before they land on disk. Use when the user wants automatic security scanning on every file write or bash command.

Install

Run a multi-agent red team scan — 29 specialized security agents scan for 80+ attack classes including injection, auth bypass, SSRF, supply chain, Supabase RLS, MCP security, agentic AI, RAG poisoning, PII compliance, and more. Use when the user wants a deep security analysis beyond just secrets.

Install

Quick scan for leaked secrets — API keys, passwords, tokens, database URLs. Use when the user wants to check for hardcoded secrets or exposed credentials.

Install

Get your project's security health score (0-100, A-F grade). Use when the user wants a quick security check or asks "is my code safe to ship?

Install

Run a full security audit on this project — 16 agents scan for secrets, injections, auth bypass, SSRF, supply chain, Supabase RLS, MCP security, agentic AI, RAG poisoning, PII compliance, and more. Use when the user wants a security audit, vulnerability scan, or asks if their code is safe to ship.

Install
Use cases

Subagents overview

README preview not available. Visit the repo on GitHub for full documentation.
agentic-aiai-securityclidevscopsllm-securitymcpnpmowaspsecretssecuritysecurity-toolsstatic-analysis

What people ask about ship-safe

What is asamassekou10/ship-safe?

+

asamassekou10/ship-safe is subagents for the Claude AI ecosystem. CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies. It has 829 GitHub stars and its last recorded update is dated 2026-09-01.

How do I install ship-safe?

+

You can install ship-safe by cloning the repository (https://github.com/asamassekou10/ship-safe) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is asamassekou10/ship-safe safe to use?

+

Our security agent has analyzed asamassekou10/ship-safe and assigned a Trust Score of 97/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.

Who maintains asamassekou10/ship-safe?

+

asamassekou10/ship-safe is maintained by asamassekou10. The last recorded GitHub activity is dated 2026-09-01, with 11 open issues.

Are there alternatives to ship-safe?

+

Yes. On ClaudeWave you can browse similar subagents at /categories/agents, sorted by popularity or recent activity.

Deploy ship-safe to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: asamassekou10/ship-safe
[![Featured on ClaudeWave](https://claudewave.com/api/badge/asamassekou10-ship-safe)](https://claudewave.com/repo/asamassekou10-ship-safe)
<a href="https://claudewave.com/repo/asamassekou10-ship-safe"><img src="https://claudewave.com/api/badge/asamassekou10-ship-safe" alt="Featured on ClaudeWave: asamassekou10/ship-safe" width="320" height="64" /></a>

More Subagents