Skip to main content
Glama
TateLyman

shipcheck-mcp

by TateLyman

shipcheck-mcp

npm version ci MCP Registry Shipcheck Action

AI 코딩 에이전트가 로컬 JavaScript 및 TypeScript 저장소에서 Shipcheck를 실행할 수 있게 해주는 MCP 서버입니다.

Shipcheck는 AI로 구축된 앱에서 노출된 개인 정보처럼 보이는 환경 변수, 서명되지 않은 Stripe 웹훅, 누락된 Supabase/Firebase 규칙 증거, 디버그 경로, 누락된 AI 사용 가드레일, 누락된 CI, 느슨한 종속성, 부실한 릴리스 문서와 같은 출시 위험을 스캔합니다.

도구 페이지: https://tatelyman.github.io/tate-web-services/shipcheck.html

공식 MCP 레지스트리: https://registry.modelcontextprotocol.io/v0/servers?search=shipcheck

GitHub 코드 스캔 알림이 포함된 데모 저장소: https://github.com/TateLyman/shipcheck-demo-ai-app

설치

npx로 직접 실행:

npx --yes shipcheck-mcp

Related MCP server: CodeInspectus

MCP 설정

stdio 서버를 지원하는 MCP 클라이언트에 이 서버를 추가하세요:

{
  "mcpServers": {
    "shipcheck": {
      "command": "npx",
      "args": ["--yes", "--package", "shipcheck-mcp", "shipcheck-mcp"]
    }
  }
}

도구

scan_repository

{
  "root": ".",
  "format": "markdown",
  "failOn": "medium",
  "strict": true
}

형식: text, markdown, json 또는 sarif.

심각도: info, low, medium 또는 high.

Shipcheck는 방어적 정적 분석이며 모의 해킹이 아닙니다. 본인이 소유하거나 검사 권한이 있는 저장소에서만 실행하세요.

개발

npm install
npm run check

Available Tools

1 tool
scan_repositoryScan repository with ShipcheckB

Run Shipcheck on a local JavaScript or TypeScript repo the user owns or is authorized to inspect.

ParametersJSON Schema
NameRequiredDescriptionDefault
rootNoLocal path to the repository root..
formatNoReport format to return.text
failOnNoLowest severity that should mark the report as failing.high
strictNoEnable stricter release-readiness checks.

TDQS

B3.4/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must disclose behavioral traits. It only hints at authorization but does not state whether the operation is read-only, modifies files, requires network, or has rate limits. This is insufficient for a scanning tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single sentence with no redundant words. It is front-loaded with the action and conditions, making it efficient and easy to parse.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness2/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

Despite having 4 parameters and no output schema, the description does not explain what Shipcheck is, what the report contains, or how the 'failOn' and 'strict' parameters affect behavior. This leaves significant gaps for an agent to select the tool confidently.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so each parameter is already documented. The overall description adds context about the tool being for JS/TS repos, but does not enhance parameter meaning beyond what the schema provides. Baseline score of 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb (Run Shipcheck), the resource (local JavaScript or TypeScript repo), and includes an authorization condition. No sibling tools exist, so differentiation is not required.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description implies usage on local JS/TS repos the user is authorized to inspect, but does not provide explicit guidance on when to use or when not to use it, nor any alternatives since there are no siblings.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 1 tool updatev0.1.3
    • First observedscan_repository

TDQS

A3.6/5.0

Scored across 1 tool

Disambiguation5/5

With only one tool, there is no chance of confusion between tools. The single tool has a clear and distinct purpose.

Naming Consistency5/5

With only one tool, there are no naming inconsistencies. The name 'scan_repository' follows a clear snake_case convention.

Tool Count3/5

A single tool feels thin for most purposes, though for a very specialized server like 'shipcheck' it might be acceptable. It borders on too minimal.

Completeness3/5

The server only offers one operation (scanning), which may be insufficient for a full workflow. Missing potential tools like listing results or configuration, but the core task is covered.

Maintenance

ActivityInactive
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    Local-first security check for AI coding agents — finds hardcoded secrets, exposed .env files, git-history leaks and vulnerable dependencies (OSV), entirely on your machine. Ask your agent "is this safe to ship?" and get a Launch Readiness score with a fix for every finding.
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Local-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.
    7
    104 npm
    47
    Apache 2.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to analyze code health in TypeScript/JavaScript projects, providing tools to run analysis, start a dashboard, and get summaries.
    15 npm
    3
    MIT
  • F
    license
    A
    quality
    D
    maintenance
    Enables AI agents to screen GitHub repositories and pull requests for risk analysis, generating risk scores, findings, and merge-readiness signals.
    5
    -