Skip to main content

● MCP Server

Scan as your agent writes.

The ShipSafe MCP server lets your AI coding agent scan the code it writes for security vulnerabilities, in-loop, without leaving the editor. Works in Cursor, Claude Code, and Claude Desktop. Your code is never stored.

▸ Tools

Tools

Three tools your agent can call. Most of the time it just needs shipsafe_scan.

shipsafe_scanScan a directory for vulnerabilities — secrets, injection, broken auth/IDOR, misconfiguration, and known-CVE dependencies. Returns plain-English findings with the exact fix, plus a structured clean/not-clean verdict the agent can branch on.Free (local + dependency scan). AI deep analysis needs Growth or Shield.
shipsafe_fix_promptScan, then return one paste-ready prompt covering every finding in that scan, tailored to the detected AI builder. You paste it; your builder makes the change.Growth / Shield
shipsafe_statusShow login state, plan, and remaining AI scan quota.—

▸ Setup

Set up your editor

Point your agent at the ShipSafe MCP server, then ask it to “scan this project with ShipSafe and fix what it finds.”

▸ Claude Code

TERMINAL
claude mcp add shipsafe -- npx -y @ship-safe/mcp

▸ Cursor

Add to Cursor

What happens next. Cursor opens a box called Install MCP server? and asks you to confirm. It will show shipsafe as the name and npx -y @ship-safe/mcp as the command — that is the scanner, downloaded from npm. Leave Secrets empty; you do not need one to start. Then press Install.

Cursor also warns that an MCP server runs with your own permissions. That is true of every MCP server, including this one, and it is worth reading rather than clicking past. It is the reason the scan runs on your machine instead of ours — your code and your keys never have to leave it.

Or add it to .cursor/mcp.json (project) or ~/.cursor/mcp.json (global):

JSON·mcp.json
{
  "mcpServers": {
    "shipsafe": {"command":"npx","args":["-y","@ship-safe/mcp"]}
  }
}

▸ Claude Desktop

Add the same block to claude_desktop_config.json:

JSON·claude_desktop_config.json
{
  "mcpServers": {
    "shipsafe": {"command":"npx","args":["-y","@ship-safe/mcp"]}
  }
}

▸ Smithery

ShipSafe is also listed on Smithery, as the same local server: smithery.ai/servers/ship-safe/shipsafe

▸ Login

Log in for AI analysis

The free local pattern and dependency scan works with no login. The MCP server reuses the ShipSafe CLI’s session, so a single login unlocks AI deep analysis: a free account includes one AI scan, and fix prompts come with the monthly plans. Once, in a terminal:

TERMINAL
npx -y @ship-safe/cli login