Skip to main content
Glama
TateLyman

shipcheck-mcp

by TateLyman

shipcheck-mcp

npm version ci MCP Registry Shipcheck Action

MCP-Server, der es KI-Coding-Agenten ermöglicht, Shipcheck auf lokalen JavaScript- und TypeScript-Repositories auszuführen.

Shipcheck scannt von KI erstellte Apps auf Startrisiken wie offengelegte, potenziell private Umgebungsvariablen, unsignierte Stripe-Webhooks, fehlende Nachweise für Supabase/Firebase-Regeln, Debug-Routen, fehlende KI-Nutzungsrichtlinien, fehlende CI, lockere Abhängigkeiten und unzureichende Release-Dokumentation.

Tool-Seite: https://tatelyman.github.io/tate-web-services/shipcheck.html

Offizielles MCP-Register: https://registry.modelcontextprotocol.io/v0/servers?search=shipcheck

Demo-Repo mit GitHub-Code-Scanning-Warnungen: https://github.com/TateLyman/shipcheck-demo-ai-app

Installation

Direkt mit npx ausführen:

npx --yes shipcheck-mcp

Related MCP server: CodeInspectus

MCP-Konfiguration

Fügen Sie diesen Server einem MCP-Client hinzu, der stdio-Server unterstützt:

{
  "mcpServers": {
    "shipcheck": {
      "command": "npx",
      "args": ["--yes", "--package", "shipcheck-mcp", "shipcheck-mcp"]
    }
  }
}

Tool

scan_repository

{
  "root": ".",
  "format": "markdown",
  "failOn": "medium",
  "strict": true
}

Formate: text, markdown, json oder sarif.

Schweregrade: info, low, medium oder high.

Shipcheck ist eine defensive statische Analyse, kein Penetrationstest. Führen Sie es nur auf Repositories aus, die Sie besitzen oder für die Sie eine Inspektionsberechtigung haben.

Entwicklung

npm install
npm run check

Available Tools

1 tool
scan_repositoryScan repository with ShipcheckB

Run Shipcheck on a local JavaScript or TypeScript repo the user owns or is authorized to inspect.

ParametersJSON Schema
NameRequiredDescriptionDefault
rootNoLocal path to the repository root..
formatNoReport format to return.text
failOnNoLowest severity that should mark the report as failing.high
strictNoEnable stricter release-readiness checks.

TDQS

B3.4/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must disclose behavioral traits. It only hints at authorization but does not state whether the operation is read-only, modifies files, requires network, or has rate limits. This is insufficient for a scanning tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence with no redundant words. It is front-loaded with the action and conditions, making it efficient and easy to parse.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite having 4 parameters and no output schema, the description does not explain what Shipcheck is, what the report contains, or how the 'failOn' and 'strict' parameters affect behavior. This leaves significant gaps for an agent to select the tool confidently.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so each parameter is already documented. The overall description adds context about the tool being for JS/TS repos, but does not enhance parameter meaning beyond what the schema provides. Baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb (Run Shipcheck), the resource (local JavaScript or TypeScript repo), and includes an authorization condition. No sibling tools exist, so differentiation is not required.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage on local JS/TS repos the user is authorized to inspect, but does not provide explicit guidance on when to use or when not to use it, nor any alternatives since there are no siblings.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev0.1.3
    • First observedscan_repository

TDQS

A3.6/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is no chance of confusion between tools. The single tool has a clear and distinct purpose.

Naming Consistency5/5

With only one tool, there are no naming inconsistencies. The name 'scan_repository' follows a clear snake_case convention.

Tool Count3/5

A single tool feels thin for most purposes, though for a very specialized server like 'shipcheck' it might be acceptable. It borders on too minimal.

Completeness3/5

The server only offers one operation (scanning), which may be insufficient for a full workflow. Missing potential tools like listing results or configuration, but the core task is covered.

Maintenance

ActivityInactive
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Local-first security check for AI coding agents — finds hardcoded secrets, exposed .env files, git-history leaks and vulnerable dependencies (OSV), entirely on your machine. Ask your agent "is this safe to ship?" and get a Launch Readiness score with a fix for every finding.
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.
    7
    104 npm
    47
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to analyze code health in TypeScript/JavaScript projects, providing tools to run analysis, start a dashboard, and get summaries.
    15 npm
    3
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Enables AI agents to screen GitHub repositories and pull requests for risk analysis, generating risk scores, findings, and merge-readiness signals.
    5
    -