shipcheck-mcp
shipcheck-mcp
AI 코딩 에이전트가 로컬 JavaScript 및 TypeScript 저장소에서 Shipcheck를 실행할 수 있게 해주는 MCP 서버입니다.
Shipcheck는 AI로 구축된 앱에서 노출된 개인 정보처럼 보이는 환경 변수, 서명되지 않은 Stripe 웹훅, 누락된 Supabase/Firebase 규칙 증거, 디버그 경로, 누락된 AI 사용 가드레일, 누락된 CI, 느슨한 종속성, 부실한 릴리스 문서와 같은 출시 위험을 스캔합니다.
도구 페이지: https://tatelyman.github.io/tate-web-services/shipcheck.html
공식 MCP 레지스트리: https://registry.modelcontextprotocol.io/v0/servers?search=shipcheck
GitHub 코드 스캔 알림이 포함된 데모 저장소: https://github.com/TateLyman/shipcheck-demo-ai-app
설치
npx로 직접 실행:
npx --yes shipcheck-mcpRelated MCP server: CodeInspectus
MCP 설정
stdio 서버를 지원하는 MCP 클라이언트에 이 서버를 추가하세요:
{
"mcpServers": {
"shipcheck": {
"command": "npx",
"args": ["--yes", "--package", "shipcheck-mcp", "shipcheck-mcp"]
}
}
}도구
scan_repository
{
"root": ".",
"format": "markdown",
"failOn": "medium",
"strict": true
}형식: text, markdown, json 또는 sarif.
심각도: info, low, medium 또는 high.
Shipcheck는 방어적 정적 분석이며 모의 해킹이 아닙니다. 본인이 소유하거나 검사 권한이 있는 저장소에서만 실행하세요.
개발
npm install
npm run checkAvailable Tools
1 toolscan_repositoryScan repository with ShipcheckB
Run Shipcheck on a local JavaScript or TypeScript repo the user owns or is authorized to inspect.
| Name | Required | Description | Default |
|---|---|---|---|
| root | No | Local path to the repository root. | . |
| format | No | Report format to return. | text |
| failOn | No | Lowest severity that should mark the report as failing. | high |
| strict | No | Enable stricter release-readiness checks. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description must disclose behavioral traits. It only hints at authorization but does not state whether the operation is read-only, modifies files, requires network, or has rate limits. This is insufficient for a scanning tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence with no redundant words. It is front-loaded with the action and conditions, making it efficient and easy to parse.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Despite having 4 parameters and no output schema, the description does not explain what Shipcheck is, what the report contains, or how the 'failOn' and 'strict' parameters affect behavior. This leaves significant gaps for an agent to select the tool confidently.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so each parameter is already documented. The overall description adds context about the tool being for JS/TS repos, but does not enhance parameter meaning beyond what the schema provides. Baseline score of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the verb (Run Shipcheck), the resource (local JavaScript or TypeScript repo), and includes an authorization condition. No sibling tools exist, so differentiation is not required.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies usage on local JS/TS repos the user is authorized to inspect, but does not provide explicit guidance on when to use or when not to use it, nor any alternatives since there are no siblings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v0.1.3- First observed
scan_repository
TDQS
Scored across 1 tool
With only one tool, there is no chance of confusion between tools. The single tool has a clear and distinct purpose.
With only one tool, there are no naming inconsistencies. The name 'scan_repository' follows a clear snake_case convention.
A single tool feels thin for most purposes, though for a very specialized server like 'shipcheck' it might be acceptable. It borders on too minimal.
The server only offers one operation (scanning), which may be insufficient for a full workflow. Missing potential tools like listing results or configuration, but the core task is covered.
Maintenance
Related MCP Connectors
Open-source licence risk checks for AI coding agents and dependency trees.
Deep security scans of repos you own from your editor: dependency CVEs, SAST, git-history secrets.
check-package: block malicious npm/PyPI deps before your AI agent installs them. Free, no key.
Stateless TS/JS compiler facts for agents: references, imports, impact. No repo index or OAuth.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceLocal-first security check for AI coding agents — finds hardcoded secrets, exposed .env files, git-history leaks and vulnerable dependencies (OSV), entirely on your machine. Ask your agent "is this safe to ship?" and get a Launch Readiness score with a fix for every finding.MIT
- AlicenseAqualityAmaintenanceLocal-first, zero-egress security scanner for AI-generated / "vibe-coded" JS/TS. Bundles Opengrep, Gitleaks & Trivy behind one CWE-keyed schema and adds AI-code-specific checks (client-side secret exposure, Supabase RLS, prompt-injection & LLM-output XSS sinks). No account, no telemetry.7104 npm47Apache 2.0
- AlicenseNot gradedqualityDmaintenanceEnables AI assistants to analyze code health in TypeScript/JavaScript projects, providing tools to run analysis, start a dashboard, and get summaries.15 npm3MIT

gitlumen-mcpofficial
FlicenseAqualityDmaintenanceEnables AI agents to screen GitHub repositories and pull requests for risk analysis, generating risk scores, findings, and merge-readiness signals.5-